CVE-2019-10437: CSRF
A cross-site request forgery vulnerability in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier allowed attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Other sources
A cross-site request forgery vulnerability in Jenkins CRX Content Package Deployer Plugin prior to 1.9 allowed attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. This issue is patched in version 1.9
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10437?
CVE-2019-10437 is considered a high severity vulnerability due to its ability to exploit cross-site request forgery.
How do I fix CVE-2019-10437?
To fix CVE-2019-10437, update the Jenkins CRX Content Package Deployer Plugin to version 1.9 or later.
What type of vulnerability is CVE-2019-10437?
CVE-2019-10437 is a cross-site request forgery (CSRF) vulnerability.
What software is affected by CVE-2019-10437?
CVE-2019-10437 affects Jenkins CRX Content Package Deployer Plugin versions 1.8.1 and earlier.
What can attackers do with CVE-2019-10437?
Attackers can exploit CVE-2019-10437 to connect to an attacker-specified URL using credentials stored in Jenkins.