{"api_version":"1","generated_at":"2026-07-23T11:58:57+00:00","cve":"CVE-2019-10354","urls":{"html":"https://cve.report/CVE-2019-10354","api":"https://cve.report/api/cve/CVE-2019-10354.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-10354","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-10354"},"summary":{"title":"CVE-2019-10354","description":"A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attackers to access view fragments directly, bypassing permission checks and possibly obtain sensitive information.","state":"PUBLIC","assigner":"jenkinsci-cert@googlegroups.com","published_at":"2019-07-17 16:15:00","updated_at":"2023-10-25 18:16:00"},"problem_types":["CWE-862"],"metrics":[],"references":[{"url":"https://jenkins.io/security/advisory/2019-07-17/#SECURITY-534","name":"https://jenkins.io/security/advisory/2019-07-17/#SECURITY-534","refsource":"MISC","tags":["Vendor Advisory"],"title":"Jenkins Security Advisory 2019-07-17","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2019:2548","name":"RHSA-2019:2548","refsource":"REDHAT","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2019/07/17/2","name":"[oss-security] 20190717 Multiple vulnerabilities in Jenkins","refsource":"MLIST","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - Multiple vulnerabilities in Jenkins","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/109373","name":"109373","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Jenkins Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://access.redhat.com/errata/RHSA-2019:2503","name":"RHSA-2019:2503","refsource":"REDHAT","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-10354","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-10354","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"10354","vulnerable":"1","versionEndIncluding":"2.176.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"jenkins","cpe5":"jenkins","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"lts","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"10354","vulnerable":"1","versionEndIncluding":"2.185","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"jenkins","cpe5":"jenkins","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"-","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"10354","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"openshift_container_platform","cpe6":"3.11","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"10354","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"openshift_container_platform","cpe6":"4.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"10354","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"openshift_container_platform","cpe6":"3.11","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"10354","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"openshift_container_platform","cpe6":"4.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2019-10354","ASSIGNER":"jenkinsci-cert@googlegroups.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attackers to access view fragments directly, bypassing permission checks and possibly obtain sensitive information."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Jenkins project","product":{"product_data":[{"product_name":"Jenkins","version":{"version_data":[{"version_affected":"=","version_value":"2.185 and earlier, LTS 2.176.1 and earlier"}]}}]}}]}},"references":{"reference_data":[{"url":"http://www.openwall.com/lists/oss-security/2019/07/17/2","refsource":"MISC","name":"http://www.openwall.com/lists/oss-security/2019/07/17/2"},{"url":"http://www.securityfocus.com/bid/109373","refsource":"MISC","name":"http://www.securityfocus.com/bid/109373"},{"url":"https://access.redhat.com/errata/RHSA-2019:2503","refsource":"MISC","name":"https://access.redhat.com/errata/RHSA-2019:2503"},{"url":"https://access.redhat.com/errata/RHSA-2019:2548","refsource":"MISC","name":"https://access.redhat.com/errata/RHSA-2019:2548"},{"url":"https://jenkins.io/security/advisory/2019-07-17/#SECURITY-534","refsource":"MISC","name":"https://jenkins.io/security/advisory/2019-07-17/#SECURITY-534"}]}},"nvd":{"publishedDate":"2019-07-17 16:15:00","lastModifiedDate":"2023-10-25 18:16:00","problem_types":["CWE-862"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*","versionEndIncluding":"2.176.1","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*","versionEndIncluding":"2.185","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:redhat:openshift_container_platform:4.1:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"10354","Ordinal":"148582","Title":"CVE-2019-10354","CVE":"CVE-2019-10354","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"10354","Ordinal":"1","NoteData":"A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attackers to access view fragments directly, bypassing permission checks and possibly obtain sensitive information.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"10354","Ordinal":"2","NoteData":"2019-07-17","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"10354","Ordinal":"3","NoteData":"2019-09-19","Type":"Other","Title":"Modified"}]}}}