Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix for CVE-2019-1003004 in these releases did not reject existing remoting-based CLI authentication caches.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: jenkins

Published: 2019-04-10T20:12:29

Updated: 2023-10-24T16:45:27.954Z

Reserved: 2019-04-10T00:00:00


Link: CVE-2019-1003049

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2019-04-10T21:29:01.480

Modified: 2023-10-25T18:16:04.353


Link: CVE-2019-1003049

JSON object: View

cve-icon Redhat Information

No data.

CWE