S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2019-10405 Scanner

CVE-2019-10405 scanner - Information Disclosure vulnerability in Jenkins

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.3k
Times Used
continuous scan runs
4.3k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-10405
5.4
CVSS

Jenkins 2.196 and earlier, LTS 2.176.3 and earlier printed the value of the "Cookie" HTTP request header on the /whoAmI/ URL, allowing attackers exploiting another XSS vulnerability to obtain the HTTP session cookie despite it being marked HttpOnly.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Jenkinsby Jenkins project
2.196 and earlier, LTS 2.176.3 and earlier
Updated Aug 21, 2026View on NVD →
Detail

Jenkins is a popular automation server used by development teams for building, testing, and deploying software. It helps streamline the software development process by automating repetitive tasks and managing the build and release pipeline. Its open-source nature has contributed to its widespread usage in various organizations. Jenkins is highly customizable and can be integrated with various tools and plugins to facilitate continuous integration/continuous deployment (CI/CD) processes.

However, vulnerabilities like CVE-2019-10405 have been detected in Jenkins, which can pose significant security risks to organizations using the tool. This vulnerability allowed attackers to exploit an XSS (Cross-Site Scripting) vulnerability and obtain the HTTP session cookie despite it being marked as HttpOnly. As a result, attackers could access the user's session and perform unauthorized actions on the Jenkins server.

When this vulnerability is exploited, attackers can gain control over the Jenkins server and access sensitive information or modify the build and release pipeline, leading to potential downtime and delays in the software development process. As Jenkins is often used in CI/CD pipelines, any disruption can cause significant losses in terms of time and money for the organization.

In conclusion, using Jenkins can significantly improve the software development process for organizations, but it is crucial to ensure that the tool is protected against vulnerabilities like CVE-2019-10405. s4e.io is a platform that offers pro features to help organizations quickly and easily detect vulnerabilities in their digital assets, ensuring the security of their systems and preventing any potential security incidents or breaches. Invest in security measures to ensure that your organization's software development process remains secure.

 

REFERENCES

Solution Advice

To protect against this vulnerability, organizations using Jenkins can take the following precautions:

  • Update to the latest version of Jenkins to ensure that the vulnerability is patched.
  • Implement strict CSRF (Cross-Site Request Forgery) protection to prevent unauthorized access to the server.
  • Implement strict XSS protection to prevent attackers from injecting malicious scripts or accessing cookies.
  • Restrict permissions for users and ensure that only necessary users have access to the Jenkins server.
  • Enable two-factor authentication to prevent unauthorized access even if a user's credentials are compromised.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-10405 scanner - Information Disclosure vulnerability in Jenkins | S4E