Description
Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session ID, resulting in CSRF tokens that did not expire and could be used to bypass CSRF protection for the anonymous user.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/08/28/4
https://access.redhat.com/errata/RHSA-2019:2789
https://access.redhat.com/errata/RHSA-2019:3144
https://jenkins.io/security/advisory/2019-08-28/#SECURITY-1491
https://www.oracle.com/security-alerts/cpuapr2022.html
Related Vulnerabilities
CVE-2022-37266 Vulnerability in npm package steal
CVE-2022-45693 Vulnerability in maven package org.codehaus.jettison:jettison
CVE-2024-36401 Vulnerability in maven package org.geoserver:gs-wfs
CVE-2019-19771 Vulnerability in npm package bitcoijns-lib
CVE-2020-2126 Vulnerability in maven package com.dubture.jenkins:digitalocean-plugin