CVE-2019-10354: Jenkins
Medium severity, CVSS 4.3. EPSS: 1.6% chance of exploitation in the next 30 days.
A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attackers to access view fragments directly, bypassing permission checks and possibly obtain sensitive information.
Affected products
- Jenkins Jenkins: up to and including 2.176.1; up to and including 2.185
- Red Hat Openshift Container Platform: version 3.11 only; version 4.1 only
Published 2019-07-17. Last modified 2026-06-17.