VDB
CVE-2019-10354
CVE-2019-10354
PUBLISHED
CVSS 4 MEDIUM
A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attackers to access view fragments directly, bypassing permission checks and possibly obtain sensitive information.
EPSS 1.65% · 74.6th percentile
Risk Scores
CVSS 2.0
4
EPSS Score
1.65%
74.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Maven | org.jenkins-ci.main:jenkins-core | 0, 2.177 |
| Jenkins project | Jenkins | * |
| Maven | org.kohsuke.stapler:stapler-parent | 0 |
| jenkins | jenkins | 0, 0 |
| redhat | openshift_container_platform | 3.11, 4.1 |
Timeline
- Jul 17, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jun 28, 2022 CVE Updated
- Sep 5, 2022 EPSS Score
References
- 109373 vdb
- RHSA-2019:2548 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-10354 advisory
- https://github.com/jenkinsci/jenkins/commit/279d8109eddb7a494428baf25af9756c2e33576b url
- https://github.com/jenkinsci/stapler/commit/19637555a9f32d3875356b47234131d8b1e9fee4 url
- https://access.redhat.com/errata/RHSA-2019:2503 url
- http://www.openwall.com/lists/oss-security/2019/07/17/2 url
- https://jenkins.io/security/advisory/2019-07-17/#SECURITY-534 advisory