Medium severity4.3NVD Advisory· Published Jul 17, 2019· Updated Jun 17, 2026
CVE-2019-10354
CVE-2019-10354
Description
A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attackers to access view fragments directly, bypassing permission checks and possibly obtain sensitive information.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.main:jenkins-coreMaven | < 2.176.2 | 2.176.2 |
org.jenkins-ci.main:jenkins-coreMaven | >= 2.177, < 2.186 | 2.186 |
org.kohsuke.stapler:stapler-parentMaven | < 1.257.1 | 1.257.1 |
Affected products
7cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*+ 2 more
- cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*range: <=2.185
- cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*range: <=2.176.1
- (no CPE)range: 2.185 and earlier, LTS 2.176.1 and earlier
cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:4.1:*:*:*:*:*:*:*
- ghsa-coords2 versions
< 2.176.2+ 1 more
- (no CPE)range: < 2.176.2
- (no CPE)range: < 1.257.1
Patches
Vulnerability mechanics
References
9- www.openwall.com/lists/oss-security/2019/07/17/2nvdMailing ListThird Party AdvisoryWEB
- www.securityfocus.com/bid/109373nvdThird Party AdvisoryVDB Entry
- access.redhat.com/errata/RHSA-2019:2503nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:2548nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-6jfc-mc97-c7wgghsaADVISORY
- jenkins.io/security/advisory/2019-07-17/nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2019-10354ghsaADVISORY
- github.com/jenkinsci/jenkins/commit/279d8109eddb7a494428baf25af9756c2e33576bghsaWEB
- github.com/jenkinsci/stapler/commit/19637555a9f32d3875356b47234131d8b1e9fee4ghsaWEB
News mentions
0No linked articles in our index yet.