A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attackers to access view fragments directly, bypassing permission checks and possibly obtain sensitive information.
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2019/07/17/2 | Mailing List Third Party Advisory |
http://www.securityfocus.com/bid/109373 | Third Party Advisory VDB Entry |
https://access.redhat.com/errata/RHSA-2019:2503 | Third Party Advisory |
https://access.redhat.com/errata/RHSA-2019:2548 | Third Party Advisory |
https://jenkins.io/security/advisory/2019-07-17/#SECURITY-534 | Vendor Advisory |
http://www.openwall.com/lists/oss-security/2019/07/17/2 | Mailing List Third Party Advisory |
http://www.securityfocus.com/bid/109373 | Third Party Advisory VDB Entry |
https://access.redhat.com/errata/RHSA-2019:2503 | Third Party Advisory |
https://access.redhat.com/errata/RHSA-2019:2548 | Third Party Advisory |
https://jenkins.io/security/advisory/2019-07-17/#SECURITY-534 | Vendor Advisory |
Configurations
History
21 Nov 2024, 04:18
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.openwall.com/lists/oss-security/2019/07/17/2 - Mailing List, Third Party Advisory | |
References | () http://www.securityfocus.com/bid/109373 - Third Party Advisory, VDB Entry | |
References | () https://access.redhat.com/errata/RHSA-2019:2503 - Third Party Advisory | |
References | () https://access.redhat.com/errata/RHSA-2019:2548 - Third Party Advisory | |
References | () https://jenkins.io/security/advisory/2019-07-17/#SECURITY-534 - Vendor Advisory |
Information
Published : 2019-07-17 16:15
Updated : 2024-11-21 04:18
NVD link : CVE-2019-10354
Mitre link : CVE-2019-10354
CVE.ORG link : CVE-2019-10354
JSON object : View
Products Affected
redhat
- openshift_container_platform
jenkins
- jenkins
CWE
CWE-862
Missing Authorization