CVE-2019-10354: Medium severity jenkins lts vulnerability

Published Jul 17, 2019
·
Updated

A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attackers to access view fragments directly, bypassing permission checks and possibly obtain sensitive information.

Other sources

A vulnerability was found in Jenkins versions weekly before 2.186 and LTS before 2.176.2. Jenkins uses the Stapler web framework to render its UI views. These views are frequently comprised of several view fragments, enabling plugins to extend existing views with more content. In some cases attackers could directly access a view fragment containing sensitive information, bypassing any permission checks in the corresponding view.

Red Hat

Affected Software

9 affected componentsFixes available
maven/org.kohsuke.stapler:stapler-parent<1.257.1
1.257.1
maven/org.jenkins-ci.main:jenkins-core>=2.177<=2.185
2.186
maven/org.jenkins-ci.main:jenkins-core<=2.176.1
2.176.2
redhat/jenkins weekly<2.186
2.186
redhat/Jenkins LTS<2.176.2
2.176.2
Jenkins Jenkins<=2.176.1
Jenkins Jenkins<=2.185
redhat OpenShift Container Platform=3.11
redhat OpenShift Container Platform=4.1

Event History

Jul 17, 2019
CVE Published
via MITRE·03:45 PM
Data Sourced
via MITRE·03:45 PM
Description
May 24, 2022
Advisory Published
04:50 PM

Frequently Asked Questions

1

What is the severity of CVE-2019-10354?

CVE-2019-10354 is classified as a high severity vulnerability.

2

How do I fix CVE-2019-10354?

To fix CVE-2019-10354, you should upgrade to Jenkins version 2.186 or Stapler version 1.257.1.

3

What versions of Jenkins are affected by CVE-2019-10354?

CVE-2019-10354 affects Jenkins versions 2.185 and earlier, as well as LTS versions 2.176.1 and earlier.

4

Can CVE-2019-10354 lead to data exposure?

Yes, CVE-2019-10354 allows attackers to bypass permission checks, potentially leading to sensitive information exposure.

5

Is there a specific package associated with CVE-2019-10354?

Yes, the Stapler web framework used in Jenkins is the specific package associated with CVE-2019-10354.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203