Related Vulnerabilities: CVE-2019-10354  

A security issue has been found in Jenkins before 2.186. Jenkins uses the Stapler web framework to render its UI views. These views are frequently comprised of several view fragments, enabling plugins to extend existing views with more content. In some cases attackers could directly access a view fragment containing sensitive information, bypassing any permission checks in the corresponding view.

Severity High

Remote Yes

Type Access restriction bypass

Description

A security issue has been found in Jenkins before 2.186. Jenkins uses the Stapler web framework to render its UI views. These views are frequently comprised of several view fragments, enabling plugins to extend existing views with more content. In some cases attackers could directly access a view fragment containing sensitive information, bypassing any permission checks in the corresponding view.

AVG-1012 jenkins 2.185-1 2.186-1 High Fixed

https://jenkins.io/security/advisory/2019-07-17/