Description
CSRF tokens in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier did not expire, thereby allowing attackers able to obtain them to bypass CSRF protection.
Remediation
References
Related Vulnerabilities
WordPress Plugin Custom 404 Pro Cross-Site Scripting (3.2.8)
Microsoft SQL Server Other Vulnerability (CVE-2000-0199)
WordPress Plugin Quotes Collection Cross-Site Request Forgery (1.5.5.1)
MySQL CVE-2016-9843 Vulnerability (CVE-2016-9843)
WordPress Plugin Connector for Gravity Forms and Google Sheets Cross-Site Scripting (1.1.0)