CVE-2018-1000409: Jenkins
Medium severity, CVSS 5.4. EPSS: 1.2% chance of exploitation in the next 30 days.
A session fixation vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that prevented Jenkins from invalidating the existing session and creating a new one when a user signed up for a new user account.
Affected products
- Jenkins Jenkins: up to and including 2.138.1; up to and including 2.145
Published 2019-01-09. Last modified 2026-06-17.