Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

Jenkins < 2.192 and < 2.176.3 LTS Multiple Vulnerabilities (Windows)

Information

Severity

Severity

High

Family

Family

Web application abuses

CVSSv2 Base

CVSSv2 Base

7.3

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:H/Au:N/C:C/I:C/A:P

Solution Type

Solution Type

Vendor Patch

Created

Created

4 years ago

Modified

Modified

4 years ago

Summary

Jenkins is prone to multiple vulnerabilities.

Insight

Insight

Jenkins is prone to multiple vulnerabilities: - Stored XSS vulnerability in update center (CVE-2019-10383) - CSRF protection tokens for anonymous users does not expire in some circumstances (CVE-2019-10384)

Affected Software

Affected Software

Jenkins weekly up to and including 2.191 and Jenkins LTS up to and including 2.176.2

Detection Method

Detection Method

Checks if a vulnerable version is present on the target host.

Solution

Solution

Update to version 2.176.3 LTS, 2.192 weekly or later.

Common Vulnerabilities and Exposures (CVE)