A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attackers to access view fragments directly, bypassing permission checks and possibly obtain sensitive information.
References
Link | Resource |
---|---|
https://jenkins.io/security/advisory/2019-07-17/#SECURITY-534 | Vendor Advisory |
http://www.openwall.com/lists/oss-security/2019/07/17/2 | Mailing List Third Party Advisory |
http://www.securityfocus.com/bid/109373 | Third Party Advisory VDB Entry |
https://access.redhat.com/errata/RHSA-2019:2503 | Third Party Advisory |
https://access.redhat.com/errata/RHSA-2019:2548 | Third Party Advisory |
Information
Published : 2019-07-17 09:15
Updated : 2020-10-02 07:29
NVD link : CVE-2019-10354
Mitre link : CVE-2019-10354
JSON object : View
CWE
CWE-862
Missing Authorization
Products Affected
redhat
- openshift_container_platform
jenkins
- jenkins