jenkins: CSRF protection tokens did not expire (SECURITY-626)
Published Jul 17, 2019
7.5
HIGHCVSS 3.0
EPSS 1.50%
Description
CSRF tokens in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier did not expire, thereby allowing attackers able to obtain them to bypass CSRF protection.
Affected products
-
- Version 2.185 and earlier, LTS 2.176.1 and earlierStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Jenkins project | Jenkins | n/a |
|
No data.
Red Hat OpenShift Container Platform 3.11
jenkins-0:2.176.2.1563460897-1.el7
Fixed · RHSA-2019:2503
Red Hat OpenShift Container Platform 4.1
jenkins-0:2.176.2.1563461785-1.el7
Fixed · RHSA-2019:2548
Red Hat OpenShift Container Platform 3.10
jenkins
Will not fix
Red Hat OpenShift Container Platform 3.6
jenkins
Will not fix
Red Hat OpenShift Container Platform 3.7
jenkins
Will not fix
Red Hat OpenShift Container Platform 3.9
jenkins
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | jenkins-0:2.176.2.1563460897-1.el7 | Fixed | RHSA-2019:2503 |
| Red Hat OpenShift Container Platform 4.1 | jenkins-0:2.176.2.1563461785-1.el7 | Fixed | RHSA-2019:2548 |
| Red Hat OpenShift Container Platform 3.10 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.6 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.7 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.9 | jenkins | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- http://www.openwall.com/lists/oss-security/2019/07/17/2 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/109373 vdb-entryx_refsource_BID
- https://access.redhat.com/errata/RHSA-2019:2503 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:2548 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2019-10353 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1730877 Issue Tracking
- https://github.com/advisories/GHSA-hcxf-rq72-h4rr Advisory
- https://github.com/jenkinsci/jenkins/commit/772152315aa0a9ba27b812a4ba0f3f9b64af78d9
- https://jenkins.io/security/advisory/2019-07-17/#SECURITY-626 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-10353
- https://www.cve.org/CVERecord?id=CVE-2019-10353
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2019/07/17/2 | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| http://www.securityfocus.com/bid/109373 | vdb-entryx_refsource_BID | |
| https://access.redhat.com/errata/RHSA-2019:2503 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2019:2548 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2019-10353 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1730877 | Issue Tracking | |
| https://github.com/advisories/GHSA-hcxf-rq72-h4rr | Advisory | |
| https://github.com/jenkinsci/jenkins/commit/772152315aa0a9ba27b812a4ba0f3f9b64af78d9 | ||
| https://jenkins.io/security/advisory/2019-07-17/#SECURITY-626 | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-10353 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-10353 |
Change history (0)
No recorded changes yet.