CVE-2019-10384
Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session ID, resulting in CSRF tokens that did not expire and could be used to bypass CSRF protection for the anonymous user.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.58%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session ID, resulting in CSRF tokens that did not expire and could be used to bypass CSRF protection for the anonymous user.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 1.58% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- jenkins/jenkins · oracle/communications cloud native core automated test suite · redhat/openshift container platform
- Source
- jenkinsci-cert@googlegroups.com
References
- http://www.openwall.com/lists/oss-security/2019/08/28/4Mailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2789Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3144Third Party Advisory
- https://jenkins.io/security/advisory/2019-08-28/#SECURITY-1491Vendor Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2019/08/28/4Mailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2789Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3144Third Party Advisory
- https://jenkins.io/security/advisory/2019-08-28/#SECURITY-1491Vendor Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.