CVE-2018-1000409

A session fixation vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that prevented Jenkins from invalidating the existing session and creating a new one when a user signed up for a new user account.
References
Configurations

Configuration 1

cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*
cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*

Information

Published : 2019-01-09 11:29

Updated : 2019-05-08 10:23


NVD link : CVE-2018-1000409

Mitre link : CVE-2018-1000409

Products Affected
No products.
CWE
CWE-384

Session Fixation