Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session ID, resulting in CSRF tokens that did not expire and could be used to bypass CSRF protection for the anonymous user.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: jenkins

Published: 2019-08-28T15:30:17

Updated: 2023-10-24T16:48:34.717Z

Reserved: 2019-03-29T00:00:00


Link: CVE-2019-10384

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2019-08-28T16:15:10.983

Modified: 2023-10-25T18:16:19.840


Link: CVE-2019-10384

JSON object: View

cve-icon Redhat Information

No data.

CWE