Session Fixation Vulnerability in Jenkins GitHub Authentication Plugin
CVE-2019-1003019
5.9MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 6 February 2019
What is CVE-2019-1003019?
A session fixation vulnerability has been identified in the Jenkins GitHub Authentication Plugin, specifically affecting versions 0.29 and earlier. This issue allows an unauthorized attacker to exploit a pre-authentication session, enabling them to impersonate a legitimate user. The vulnerability arises from the insufficient validation of session data in GitHubSecurityRealm.java, which could lead to potential unauthorized access and manipulation of user sessions.
Affected Version(s)
Jenkins GitHub Authentication Plugin 0.29 and earlier