SB2019041048 - Improper Authentication in Jenkins



SB2019041048 - Improper Authentication in Jenkins

Published: April 10, 2019 Updated: August 3, 2020

Security Bulletin ID SB2019041048
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Authentication (CVE-ID: CVE-2019-1003049)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix for CVE-2019-1003004 in these releases did not reject existing remoting-based CLI authentication caches.


Remediation

Install update from vendor's website.