CSRF tokens in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier did not expire, thereby allowing attackers able to obtain them to bypass CSRF protection.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade jenkins-ltsUpgrade jenkins | Jul 18, 2019 | Jul 17, 2019 |
| Jenkins 2019 07 17 | — | Upgrade Jenkins to the latest versionUpgrade Jenkins to version 2.186Upgrade Jenkins LTS to the latest versionUpgrade Jenkins LTS to version 2.176.2 | Jul 22, 2019 | Jul 17, 2019 |
| Redhat Openshift | — | Upgrade jenkins | Aug 16, 2019 | Jul 17, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub