CVE-2019-10388: CSRF
Published Aug 7, 2019
·Updated
A cross-site request forgery vulnerability in Jenkins Relution Enterprise Appstore Publisher Plugin 1.24 and earlier allows attackers to have Jenkins initiate an HTTP connection to an attacker-specified server.
Affected Software
1 affected component
jenkins Relution Enterprise Appstore Publisher Jenkins<=1.24
Event History
Aug 7, 2019
CVE Published
via MITRE·02:20 PM
Data Sourced
via MITRE·02:20 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-10388.
2
What is the severity of CVE-2019-10388?
The severity of CVE-2019-10388 is medium with a severity value of 4.3.
3
What is the affected software?
The affected software is Jenkins Relution Enterprise Appstore Publisher Plugin version 1.24 and earlier.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is 352.
5
How can I fix CVE-2019-10388?
To fix CVE-2019-10388, update Jenkins Relution Enterprise Appstore Publisher Plugin to version 1.25 or newer.