CVE-2019-10353

HIGH7.5EPSS 0.17%

Cross-Site Request Forgery in Jenkins

發布日:2022/5/24修改日:2024/2/16

描述

CSRF tokens in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier did not expire, thereby allowing attackers able to obtain them to bypass CSRF protection.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.5CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

參考連結(6)