CVE-2019-10310: CSRF
A cross-site request forgery vulnerability in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doTestTowerConnection form validation method allowed attackers permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins
Other sources
Jenkins Ansible Tower Plugin did not perform permission checks on a method implementing form validation. This allowed users with Overall/Read access to Jenkins to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Additionally, this form validation method did not require POST requests, resulting in a cross-site request forgery vulnerability.
This form validation method now requires POST requests and Overall/Administer permissions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10310?
CVE-2019-10310 is classified as a medium severity cross-site request forgery vulnerability.
How do I fix CVE-2019-10310?
To fix CVE-2019-10310, upgrade the Jenkins Ansible Tower Plugin to version 0.9.2 or later.
What software is affected by CVE-2019-10310?
CVE-2019-10310 affects Jenkins Ansible Tower Plugin versions 0.9.1 and earlier.
What kind of attack can be performed using CVE-2019-10310?
CVE-2019-10310 allows attackers to connect to an attacker-specified URL using attacker-specified credentials.
When was CVE-2019-10310 disclosed?
CVE-2019-10310 was disclosed on April 30, 2019.