Cross-Site Request Forgery in Jenkins Static Analysis Utilities Plugin
CVE-2019-10307
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 30 April 2019
What is CVE-2019-10307?
A Cross-Site Request Forgery vulnerability exists in the Jenkins Static Analysis Utilities Plugin, specifically within the DefaultGraphConfigurationView#doSave method. This security flaw allows attackers to manipulate the default graph configuration settings for all users associated with a particular job, potentially leading to unauthorized changes in project configurations without user consent. It is crucial for Jenkins administrators to apply the necessary updates to mitigate this risk and protect their CI/CD environments.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins Static Analysis Utilities Plugin 1.95 and earlier
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved