AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-10384

HIGH · CVSS 8.8 EPSS 1.58%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-08-28 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2019-10384
Severity
HIGH
CVSS
8.8
EPSS
1.58%
Jenkins

Original NVD Description

Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session ID, resulting in CSRF tokens that did not expire and could be used to bypass CSRF protection for the anonymous user.