CVE-2019-10338

CVSS v3.0 8.8 (High)
88% Progress
CVSS v2.0 6.8 (Medium)
68% Progress
EPSS 0.26 % (66th)
0.26% Progress
Affected Products 1
Advisories 2

A cross-site request forgery vulnerability in Jenkins JX Resources Plugin 1.0.36 and earlier in GlobalPluginConfiguration#doValidateClient allowed attackers to have Jenkins connect to an attacker-specified Kubernetes server, potentially leaking credentials.

Weaknesses
CWE-352
Cross-Site Request Forgery (CSRF)
CVE Status
PUBLISHED
CNA
Jenkins Project
Published Date
2019-06-11 14:29:01
(5 years ago)
Updated Date
2023-10-25 18:16:16
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Jenkins Jx Resources for Jenkins 1.0.36 and prior versions cpe:2.3:a:jenkins:jx_resources::*:*:*:*:jenkins <= 1.0.36
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...