PT-2019-11799 · Cloudbees+1 · Jenkins

Jonathan Leitschuh

·

Published

2019-09-25

·

Updated

2023-11-02

·

CVE-2019-10405

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins versions 2.196 and earlier, LTS versions 2.176.3 and earlier
Description The issue allows attackers to obtain the HTTP session cookie, despite it being marked HttpOnly, by exploiting another XSS vulnerability and accessing the /whoAmI/ URL, which printed the value of the Cookie HTTP request header.
Recommendations For Jenkins versions 2.196 and earlier, and LTS versions 2.176.3 and earlier, update to a version that fixes this issue to prevent attackers from obtaining the HTTP session cookie. As a temporary workaround, consider restricting access to the /whoAmI/ URL until a patch is available. Avoid using the Cookie HTTP request header in the affected /whoAmI/ URL until the issue is resolved.

Fix

Information Disclosure

XSS

Weakness Enumeration

Related Identifiers

CVE-2019-10405
GHSA-47WC-P5CP-W7PW

Affected Products

Jenkins