CVE-2019-16553: CSRF
Published Dec 17, 2019
·Updated
A cross-site request forgery vulnerability in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier allows attackers to have Jenkins evaluate a computationally expensive regular expression.
Affected Software
2 affected componentsFixes available
maven/com.sonyericsson.jenkins.plugins.bfa:build-failure-analyzer<1.24.2
1.24.2
Jenkins Build Failure Analyzer Jenkins<=1.24.1
Event History
Dec 17, 2019
CVE Published
via MITRE·02:40 PM
Data Sourced
via MITRE·02:40 PM
Description
May 24, 2022
Advisory Published
05:03 PM
Frequently Asked Questions
1
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2019-16553.
2
What is the severity of CVE-2019-16553?
The severity of CVE-2019-16553 is high with a CVSS score of 8.8.
3
What is the affected software?
The affected software is Jenkins Build Failure Analyzer Plugin version 1.24.1 and earlier.
4
What is the description of CVE-2019-16553?
CVE-2019-16553 is a cross-site request forgery vulnerability in Jenkins Build Failure Analyzer Plugin that allows attackers to have Jenkins evaluate a computationally expensive regular expression.
5
How can I fix CVE-2019-16553?
To fix CVE-2019-16553, upgrade to a version of Jenkins Build Failure Analyzer Plugin that is later than 1.24.1.