Cross-site request forgery in Jenkins LTS and Jenkins - CVE-2019-10384

 

Cross-site request forgery in Jenkins LTS and Jenkins - CVE-2019-10384

Published: September 30, 2019


Vulnerability identifier: #VU21437
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10384
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform cross-site request forgery attacks.

The vulnerability exists due to the affected software allows users to obtain CSRF tokens without an associated web session ID. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website.


Affected software

Jenkins LTS
Jenkins
Arch Linux
Red Hat OpenShift Container Platform

How to mitigate CVE-2019-10384

Install update from vendor's website.

Jenkins LTS - update to 2.176.3
Jenkins - update to 2.192
Red Hat OpenShift Container Platform - update to 4.1.16

External References

Related Security Bulletins