CVE-2019-10468: CSRF
A cross-site request forgery vulnerability in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10468?
CVE-2019-10468 is classified as a critical vulnerability due to its potential to allow attackers to capture sensitive credentials in Jenkins.
How do I fix CVE-2019-10468?
To mitigate CVE-2019-10468, upgrade the Jenkins Kubernetes CI/CD Plugin to version 1.4 or higher.
What types of attacks are possible with CVE-2019-10468?
CVE-2019-10468 enables cross-site request forgery attacks allowing unauthorized access to Jenkins using captured credentials.
Which versions of Jenkins are affected by CVE-2019-10468?
CVE-2019-10468 affects Jenkins Kubernetes CI/CD Plugin versions up to and including 1.3.
What is the main impact of CVE-2019-10468?
The main impact of CVE-2019-10468 is the potential leakage of Jenkins stored credentials to an attacker.