CVE-2019-1003004: Insufficient Session Expiration
(updated )
An improper authorization vulnerability exists in Jenkins in core/src/main/java/hudson/security/AuthenticationProcessingFilter2.java
that allows attackers to extend the duration of active HTTP sessions indefinitely even though the user account may have been deleted in the mean time.
References
Code Behaviors & Features
Detect and mitigate CVE-2019-1003004 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →