Description
A improper authentication vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in SecurityRealm.java, TokenBasedRememberMeServices2.java that allows attackers with a valid cookie to remain logged in even if that feature is disabled.
Remediation
References
https://jenkins.io/security/advisory/2018-08-15/#SECURITY-996
Related Vulnerabilities
CVE-2022-41241 Vulnerability in maven package net.praqma:rqm-plugin
CVE-2023-35887 Vulnerability in maven package org.apache.sshd:sshd-common
CVE-2020-13959 Vulnerability in maven package org.apache.velocity.tools:velocity-tools-view
CVE-2018-1000011 Vulnerability in maven package org.jvnet.hudson.plugins.findbugs:parent
CVE-2013-5855 Vulnerability in maven package com.sun.faces:jsf-impl