CVE-2019-1003003
published 2019-01-22CVE-2019-1003003: An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in…
PriorityP340high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
1.54%
72.4th percentile
An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/TokenBasedRememberMeServices2.java that allows attackers with Overall/RunScripts permission to craft Remember Me cookies that would never expire, allowing e.g. to persist access to temporarily compromised user accounts.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | jenkins | <= 2.150.1 | — |
| jenkins | jenkins | <= 2.158 | — |
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| jenkins | jenkins_weekly | — | — |
| jenkins | monitoring_plugin | — | — |
| jenkins_project | jenkins | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
jenkins: cookie crafted using Jenkins script console allows unauthorised access to Jenkins instance
vendor_redhat·2019-01-16·CVSS 7.2
CVE-2019-1003003 [HIGH] CWE-384 jenkins: cookie crafted using Jenkins script console allows unauthorised access to Jenkins instance
jenkins: cookie crafted using Jenkins script console allows unauthorised access to Jenkins instance
An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/TokenBasedRememberMeServices2.java that allows attackers with Overall/RunScripts permission to craft Remember Me cookies that would never expire, allowing e.g. to persist access to temporarily compromised user accounts.
Package: jenkins (Red Hat OpenShift Container Platform 3.10) - Will not fix
Package: jenkins (Red Hat OpenShift Container Platform 3.2) - Out of support scope
Package: jenkins (Red Hat OpenShift Container Platform 3.3) - Out of support scope
Package: jenkins (Red Hat OpenShift Container Platform 3.4) - Out of support scope
Package: j
Jenkins
Jenkins Security Advisory 2019-01-16
vendor_jenkins·2019-01-16·CVSS 7.2
CVE-2019-1003003 [HIGH] Jenkins Security Advisory 2019-01-16
Title: Jenkins Security Advisory 2019-01-16
Jenkins Security Advisory 2019-01-16
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Jenkins (core)
Descriptions
Administrators could persist access to Jenkins using crafted 'Remember me' cookie
SECURITY-868
/
CVE-2019-1003003
Severity (CVSS):
high
Description:
OSV
Improper Authorization in Jenkins Core
osv·2022-05-13
CVE-2019-1003003 [HIGH] Improper Authorization in Jenkins Core
Improper Authorization in Jenkins Core
An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/TokenBasedRememberMeServices2.java that allows attackers with Overall/RunScripts permission to craft Remember Me cookies that would never expire, allowing e.g. to persist access to temporarily compromised user accounts.
GHSA
Improper Authorization in Jenkins Core
ghsa·2022-05-13
CVE-2019-1003003 [HIGH] CWE-285 Improper Authorization in Jenkins Core
Improper Authorization in Jenkins Core
An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/TokenBasedRememberMeServices2.java that allows attackers with Overall/RunScripts permission to craft Remember Me cookies that would never expire, allowing e.g. to persist access to temporarily compromised user accounts.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-1003003 jenkins: cookie crafted using Jenkins script console allows unauthorised access to Jenkins instance [fedora-28]
bugzilla·2019-01-22·CVSS 7.2
CVE-2019-1003003 [HIGH] CVE-2019-1003003 jenkins: cookie crafted using Jenkins script console allows unauthorised access to Jenkins instance [fedora-28]
CVE-2019-1003003 jenkins: cookie crafted using Jenkins script console allows unauthorised access to Jenkins instance [fedora-28]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-28.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
D
Bugzilla
CVE-2019-1003003 CVE-2019-1003004 jenkins: various flaws [fedora-all]
bugzilla·2019-01-22·CVSS 7.2
CVE-2019-1003003 [HIGH] CVE-2019-1003003 CVE-2019-1003004 jenkins: various flaws [fedora-all]
CVE-2019-1003003 CVE-2019-1003004 jenkins: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedo
Bugzilla
CVE-2019-1003003 jenkins: cookie crafted using Jenkins script console allows unauthorised access to Jenkins instance
bugzilla·2019-01-22·CVSS 7.2
CVE-2019-1003003 [HIGH] CVE-2019-1003003 jenkins: cookie crafted using Jenkins script console allows unauthorised access to Jenkins instance
CVE-2019-1003003 jenkins: cookie crafted using Jenkins script console allows unauthorised access to Jenkins instance
Users with the Overall/RunScripts permission (typically administrators) were able to use the Jenkins script console to craft a 'Remember me' cookie that would never expire. This allowed attackers access to a Jenkins instance while the corresponding user in the configured security realm exists, for example to persist access after another successful attack.
Discussion:
Created jenkins tracking bugs for this issue:
Affects: fedora-28 [bug 1668346]
---
External References:
https://jenkins.io/security/advisory/2019-01-16/
---
Created jenkins tracking bugs for this issue:
Affects: fedora-all [bug 1668446]
---
The v3.11 image has already been released with 2.150.2. Cust
2019-01-22
Published