VDB
CVE-2019-10353
CVE-2019-10353
PUBLISHED
CVSS 5.099999904632568 MEDIUM
CSRF tokens in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier did not expire, thereby allowing attackers able to obtain them to bypass CSRF protection.
EPSS 1.50% · 72.3th percentile
Risk Scores
CVSS 2.0
5.099999904632568
EPSS Score
1.50%
72.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| jenkins | jenkins | 0, 0 |
| Maven | org.jenkins-ci.main:jenkins-core | 0, 2.177 |
| Jenkins project | Jenkins | * |
Timeline
- Jul 17, 2019 CVE Published
- Jul 26, 2019 CVE Updated
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
References
- 109373 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2019-10353 advisory
- https://github.com/jenkinsci/jenkins/commit/772152315aa0a9ba27b812a4ba0f3f9b64af78d9 url
- https://access.redhat.com/errata/RHSA-2019:2503 url
- http://www.openwall.com/lists/oss-security/2019/07/17/2 mailing_list
- https://access.redhat.com/errata/RHSA-2019:2548 technical
- https://jenkins.io/security/advisory/2019-07-17/#SECURITY-626 advisory