ZeroHour

CVE-2019-10354

CVSS 3.1
4.3 medium
EPSS
2%p75
Published
()
Modified
Description

A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attackers to access view fragments directly, bypassing permission checks and possibly obtain sensitive information.

Vendors
jenkinsredhat
Products
jenkins, openshift container platform
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.