VulnerabilityModified
CVE-2019-10354
A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attackers to access view fragments directly, bypassing permission checks and possibly obtain sensitive information.
MEDIUM 4.3EPSS 1.65%
Does this matter?
Lower severity and a low EPSS score (1.65%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attackers to access view fragments directly, bypassing permission checks and possibly obtain sensitive information.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.65% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- jenkins/jenkins · redhat/openshift container platform
- Source
- jenkinsci-cert@googlegroups.com
References
- http://www.openwall.com/lists/oss-security/2019/07/17/2Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/109373Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:2503Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2548Third Party Advisory
- https://jenkins.io/security/advisory/2019-07-17/#SECURITY-534Vendor Advisory
- http://www.openwall.com/lists/oss-security/2019/07/17/2Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/109373Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:2503Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2548Third Party Advisory
- https://jenkins.io/security/advisory/2019-07-17/#SECURITY-534Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.