AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-1003004

HIGH · CVSS 7.2 EPSS 1.62%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-01-22 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.2. It affects Jenkins, Java.

CVE
CVE-2019-1003004
Severity
HIGH
CVSS
7.2
EPSS
1.62%
Jenkins Java

Original NVD Description

An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/AuthenticationProcessingFilter2.java that allows attackers to extend the duration of active HTTP sessions indefinitely even though the user account may have been deleted in the mean time.

Related CVEs

Other vulnerabilities affecting the same vendor(s)