Authentication bypass using an alternate path or channel in Jenkins and Jenkins LTS - CVE-2019-10354
Published: July 19, 2019 / Updated: July 22, 2019
Vulnerability identifier: #VU19268
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10354
CWE-ID: CWE-288
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass permission checks.
The vulnerability exists due to the access control bypass in the Stapler web framework. A remote authenticated attacker can access view fragments directly, bypass permission checks and possibly obtain sensitive information.
Affected software
Jenkins
Jenkins LTS
Red Hat OpenShift Container Platform
Jenkins LTS
Red Hat OpenShift Container Platform
How to mitigate CVE-2019-10354
Install updates from vendor's website.
Jenkins - update to 2.186
Jenkins LTS - update to 2.176.2
Jenkins LTS - update to 2.176.2