ZeroHour

CVE-2019-10353

CVSS 3.0
7.5 high
EPSS
2%p73
Published
()
Modified
Description

CSRF tokens in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier did not expire, thereby allowing attackers able to obtain them to bypass CSRF protection.

Vendors
jenkins
Products
jenkins
Weakness
CWE-352
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.