Cross-site request forgery in Jenkins LTS and Jenkins - CVE-2019-10384
Published: September 30, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform cross-site request forgery attacks.
The vulnerability exists due to the affected software allows users to obtain CSRF tokens without an associated web session ID. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website.
Affected software
Jenkins
Arch Linux
Red Hat OpenShift Container Platform
How to mitigate CVE-2019-10384
Jenkins - update to 2.192
Red Hat OpenShift Container Platform - update to 4.1.16