CVE-2019-10354: Medium severity jenkins lts vulnerability
A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attackers to access view fragments directly, bypassing permission checks and possibly obtain sensitive information.
Other sources
A vulnerability was found in Jenkins versions weekly before 2.186 and LTS before 2.176.2. Jenkins uses the Stapler web framework to render its UI views. These views are frequently comprised of several view fragments, enabling plugins to extend existing views with more content. In some cases attackers could directly access a view fragment containing sensitive information, bypassing any permission checks in the corresponding view.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10354?
CVE-2019-10354 is classified as a high severity vulnerability.
How do I fix CVE-2019-10354?
To fix CVE-2019-10354, you should upgrade to Jenkins version 2.186 or Stapler version 1.257.1.
What versions of Jenkins are affected by CVE-2019-10354?
CVE-2019-10354 affects Jenkins versions 2.185 and earlier, as well as LTS versions 2.176.1 and earlier.
Can CVE-2019-10354 lead to data exposure?
Yes, CVE-2019-10354 allows attackers to bypass permission checks, potentially leading to sensitive information exposure.
Is there a specific package associated with CVE-2019-10354?
Yes, the Stapler web framework used in Jenkins is the specific package associated with CVE-2019-10354.