Description
Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session ID, resulting in CSRF tokens that did not expire and could be used to bypass CSRF protection for the anonymous user.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/08/28/4
https://access.redhat.com/errata/RHSA-2019:2789
https://access.redhat.com/errata/RHSA-2019:3144
https://jenkins.io/security/advisory/2019-08-28/#SECURITY-1491
https://www.oracle.com/security-alerts/cpuapr2022.html
Related Vulnerabilities
CVE-2018-1002203 Vulnerability in maven package org.webjars.npm:unzipper
CVE-2021-29480 Vulnerability in maven package io.ratpack:ratpack-session
CVE-2020-2269 Vulnerability in maven package org.jenkins-ci.plugins:chosen-views-tabbar
CVE-2024-4367 Vulnerability in maven package org.webjars.bower:pdfjs-dist
CVE-2021-26296 Vulnerability in maven package org.apache.myfaces.core:myfaces-core-project