ZeroHour

CVE-2019-10384

CVSS 3.1
8.8 high
EPSS
2%p74
Published
()
Modified
Description

Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session ID, resulting in CSRF tokens that did not expire and could be used to bypass CSRF protection for the anonymous user.

Vendors
jenkinsoracleredhat
Products
jenkins, communications cloud native core automated test suite, openshift container platform
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.