Bug 1620346 (CVE-2018-1999045)

Summary: CVE-2018-1999045 jenkins: "Remember me" cookie was evaluated even if that feature is disabled
Product: [Other] Security Response Reporter: Sam Fowler <sfowler>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: ahardin, aos-bugs, bleanhar, bparees, ccoleman, dedgar, eparis, java-sig-commits, jgoulding, jokerman, mchappel, mizdebsk, msrb
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: jenkins 2.121.3, jenkins 2.138 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-10-25 22:16:36 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1620347, 1644532, 1644534, 1644535, 1644536, 1644537, 1644538, 1644539, 1644540, 1644541, 1644542    
Bug Blocks: 1620339    

Description Sam Fowler 2018-08-23 04:39:12 UTC
Jenkins before LTS version 2.121.3 and weekly version 2.138 do not properly disable "Remember me" cookies.

The "Remember me" feature can be disabled in the Jenkins security configuration.

This did not disable the processing of previously set "Remember me" cookies, so they still allowed users to be logged in.


External Reference:

https://jenkins.io/security/advisory/2018-08-15/#SECURITY-996

Comment 1 Sam Fowler 2018-08-23 04:39:29 UTC
Created jenkins tracking bugs for this issue:

Affects: fedora-all [bug 1620347]