SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-10354

A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attackers to access view fragments directly, bypassing permission checks and possibly obtain sensitive information.

MEDIUM 4.3EPSS 1.65%

Does this matter?

Lower severity and a low EPSS score (1.65%). Track it; it rarely justifies an emergency change on its own.

Description

A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attackers to access view fragments directly, bypassing permission checks and possibly obtain sensitive information.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
1.65% probability · 75th percentile
CISA KEV
Not listed
Weakness
CWE-862
Affected
jenkins/jenkins · redhat/openshift container platform
Source
jenkinsci-cert@googlegroups.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.