296,746
Total vulnerabilities in the database
Jenkins before 1.638 and LTS before 1.625.2 uses a publicly accessible salt to generate CSRF protection tokens, which makes it easier for remote attackers to bypass the CSRF protection mechanism via a brute force attack.
| Software | From | Fixed in |
|---|---|---|
| jenkins / jenkins | - | 1.637.x |
| redhat / openshift | - | 3.1.x |
| redhat / openshift | 2.0 | 2.0.x |
| jenkins / jenkins | - | 1.625.1.x |