CVE-2019-10384
Summary
| CVE | CVE-2019-10384 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-08-28 16:15:00 UTC |
| Updated | 2023-10-25 18:16:00 UTC |
| Description | Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session ID, resulting in CSRF tokens that did not expire and could be used to bypass CSRF protection for the anonymous user. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Jenkins | Jenkins | All | All | All | All |
| Application | Jenkins | Jenkins | All | All | All | All |
| Application | Oracle | Communications Cloud Native Core Automated Test Suite | 1.9.0 | All | All | All |
| Application | Redhat | Openshift Container Platform | 3.11 | All | All | All |
| Application | Redhat | Openshift Container Platform | 4.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Jenkins Security Advisory 2019-08-28 | MISC | jenkins.io | Vendor Advisory |
| Oracle Critical Patch Update Advisory - April 2022 | MISC | www.oracle.com | |
| Red Hat Customer Portal - Access to 24x7 support and knowledge | REDHAT | access.redhat.com | |
| oss-security - Multiple vulnerabilities in Jenkins and Jenkins plugins | MLIST | www.openwall.com | Mailing List, Third Party Advisory |
| Red Hat Customer Portal - Access to 24x7 support and knowledge | REDHAT | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.