CVE-2019-1003019

CWE-3845 documents5 sources
Severity
5.9MEDIUM
EPSS
0.0%
top 90.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 6
Latest updateMay 13

Description

An session fixation vulnerability exists in Jenkins GitHub Authentication Plugin 0.29 and earlier in GithubSecurityRealm.java that allows unauthorized attackers to impersonate another user if they can control the pre-authentication session.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages3 packages

🔴Vulnerability Details

3
OSV
GitHub Authentication Plugin session fixation vulnerability2022-05-13
GHSA
GitHub Authentication Plugin session fixation vulnerability2022-05-13
CVEList
CVE-2019-1003019: An session fixation vulnerability exists in Jenkins GitHub Authentication Plugin 02019-02-06

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2019-01-282019-01-28
CVE-2019-1003019 (MEDIUM CVSS 5.9) | An session fixation vulnerability e | cvebase.io