PT-2019-2964 · Jenkins · Jenkins

Published

2019-07-17

·

Updated

2023-10-25

·

CVE-2019-10353

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Jenkins versions 2.185 and earlier Jenkins LTS versions 2.176.1 and earlier
Description The issue is related to the absence of a web session identifier in Jenkins, which can be exploited by a remote attacker to perform a cross-site request forgery (CSRF) attack and gain unauthorized access to protected information. Specifically, CSRF tokens in affected Jenkins versions did not expire, allowing attackers who obtain them to bypass CSRF protection.
Recommendations For Jenkins versions 2.185 and earlier, update to a version where CSRF tokens expire to prevent bypassing of CSRF protection. For Jenkins LTS versions 2.176.1 and earlier, update to a version where CSRF tokens expire to prevent bypassing of CSRF protection.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-02940
CVE-2019-10353
GHSA-HCXF-RQ72-H4RR
RHSA-2019:2503
RHSA-2019:2548

Affected Products

Jenkins