CVE-2019-10354

medium

Description

A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attackers to access view fragments directly, bypassing permission checks and possibly obtain sensitive information.

References

https://jenkins.io/security/advisory/2019-07-17/#SECURITY-534

https://access.redhat.com/errata/RHSA-2019:2548

https://access.redhat.com/errata/RHSA-2019:2503

http://www.securityfocus.com/bid/109373

http://www.openwall.com/lists/oss-security/2019/07/17/2

Details

Source: Mitre, NVD

Published: 2019-07-17

Updated: 2023-10-25

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 4.3

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Severity: Medium