OSV 1.4.0 · unreviewed · 修改于 2026-09-04 02:31
发布时间
2026-09-03 02:32
GitHub 审查时间
—
NVD 发布时间
2026-09-03 00:17
源文件
advisories/unreviewed/2026/09/GHSA-42rh-v5qm-8p5w/GHSA-42rh-v5qm-8p5w.json
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember me" cookie, allowing attackers able to serve content on the same site as Jenkins to set a known session cookie in the victim's browser, which after the victim authenticates via the "remember me" cookie, grants the attacker access to Jenkins as that user.
该公告没有提供结构化的受影响软件包信息。