Database/Control plane, storage & DevOps
Jenkins: session is not rotated on remember-me login, allowing session fixation against any user
Impact
Jenkins does not issue a fresh session when a user is authenticated from the remember-me cookie, so an attacker who can plant a known session cookie in the victim's browser ends up sharing that authenticated session. If the victim is a Jenkins administrator or a job owner, the attacker inherits their access to the build system that ships images, Helm charts and model artifacts onto the GPU fleet. Compromise of a build controller is a supply-chain position, not just an account takeover: what it produces lands on every node. Affects Jenkins 2.579 and earlier and LTS 2.568.2 and earlier.
Who can reach it
Network attacker who can serve content on the same site as Jenkins (a sibling host or subdomain under the same cookie scope) and requires the victim to visit it and then be authenticated via remember-me. Attacker needs a low-privileged foothold plus victim interaction, not administrator access.
What to do
Upgrade Jenkins to 2.580 or LTS 2.568.3 per the 2026-09-02 advisory; this is a controller package update and a Jenkins restart, no node maintenance. Invalidate existing sessions and consider disabling remember-me until patched. Restarting the controller interrupts running builds, so schedule it between pipeline runs.
References
Related entries
- HPE iLO4 / iLO5: Remote code execution on the management controllerCVE-2018-7078 · HPE iLO4 / iLO5High
- HPE iLO3/4/5: Arbitrary code execution on the iLOCVE-2018-7105 · HPE iLO3/4/5High
- NetApp ONTAP Select Deploy administration utility (privilege escalation): An administrative user of the Deploy utilityCVE-2019-17272 · NetApp ONTAP Select Deploy administration utility (privilege escalation)High
- Ceph MON (CephX authentication): The monitor does not sanitize other_keys when handling CEPHX_GET_AUTH_SESSION_KEY, soCVE-2021-20288 · Ceph MON (CephX authentication)High
- AMD PSP1 Configuration Block (APCB) parsing: An out-of-bounds memory write while the platform processes the AMD PSP1CVE-2021-26344 · AMD PSP1 Configuration Block (APCB) parsingHigh
- Schneider Electric StruxureWare Data Center Expert (V7.9.2 and prior) - network settings endpoint: Code injectionCVE-2023-25549 · Schneider Electric StruxureWare Data Center Expert (V7.9.2 and prior) - network settings endpointHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.