Description
CSRF tokens in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier did not expire, thereby allowing attackers able to obtain them to bypass CSRF protection.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4127 | CSRF tokens in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier did not expire, thereby allowing attackers able to obtain them to bypass CSRF protection. |
Github GHSA |
GHSA-hcxf-rq72-h4rr | Cross-Site Request Forgery in Jenkins |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-04T22:17:20.468Z
Reserved: 2019-03-29T00:00:00.000Z
Link: CVE-2019-10353
No data.
Status : Modified
Published: 2019-07-17T16:15:12.490
Modified: 2024-11-21T04:18:57.213
Link: CVE-2019-10353
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA