A improper authentication vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in SecurityRealm.java, TokenBasedRememberMeServices2.java that allows attackers with a valid cookie to remain logged in even if that feature is disabled.
2018-08-23T18:29:00.843
2024-11-21T03:57:07.907
Modified
CVSSv3.0: 5.4 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:P/A:N
8.0
4.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | jenkins | jenkins | ≤ 2.121.2 | Yes |
| Application | jenkins | jenkins | ≤ 2.137 | Yes |