Show plain JSON{"affected_release": [{"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "activemq-0:5.9.0-6.redhat.611463.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "ImageMagick-0:6.7.2.7-5.el6_8", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "jenkins-0:1.651.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "libcgroup-0:0.40.rc1-18.el6_8", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-broker-0:1.16.3.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-broker-util-0:1.37.6.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-cron-0:1.25.4.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-diy-0:1.26.2.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-haproxy-0:1.31.6.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-jbosseap-0:2.27.4.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-jbossews-0:1.35.5.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-jenkins-0:1.29.2.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-jenkins-client-0:1.26.1.1-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-mongodb-0:1.26.2.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-mysql-0:1.31.3.3-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-nodejs-0:1.33.1.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-perl-0:1.30.2.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-php-0:1.35.4.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-python-0:1.34.3.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-ruby-0:1.32.2.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-msg-node-mcollective-0:1.30.2.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-node-proxy-0:1.26.3.1-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-node-util-0:1.38.7.1-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "rhc-0:1.38.7.1-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "rubygem-openshift-origin-admin-console-0:1.28.2.1-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "rubygem-openshift-origin-controller-0:1.38.6.4-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "rubygem-openshift-origin-frontend-haproxy-sni-proxy-0:0.5.2.1-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "rubygem-openshift-origin-msg-broker-mcollective-0:1.36.2.4-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "rubygem-openshift-origin-node-0:1.38.6.4-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "rubygem-openshift-origin-routing-daemon-0:0.26.6.1-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:0711", "cpe": "cpe:/a:redhat:openshift:3.1::el7", "package": "jenkins-0:1.642.2-1.el7", "product_name": "Red Hat OpenShift Enterprise 3.1", "release_date": "2016-05-03T00:00:00Z"}, {"advisory": "RHSA-2016:0711", "cpe": "cpe:/a:redhat:openshift:3.1::el7", "package": "jenkins-plugin-credentials-0:1.24-2.el7", "product_name": "Red Hat OpenShift Enterprise 3.1", "release_date": "2016-05-03T00:00:00Z"}, {"advisory": "RHSA-2016:0711", "cpe": "cpe:/a:redhat:openshift:3.1::el7", "package": "jenkins-plugin-durable-task-0:1.7-1.el7", "product_name": "Red Hat OpenShift Enterprise 3.1", "release_date": "2016-05-03T00:00:00Z"}, {"advisory": "RHSA-2016:0711", "cpe": "cpe:/a:redhat:openshift:3.1::el7", "package": "jenkins-plugin-kubernetes-0:0.5-1.el7", "product_name": "Red Hat OpenShift Enterprise 3.1", "release_date": "2016-05-03T00:00:00Z"}, {"advisory": "RHSA-2016:0711", "cpe": "cpe:/a:redhat:openshift:3.1::el7", "package": "jenkins-plugin-openshift-pipeline-0:1.0.9-1.el7", "product_name": "Red Hat OpenShift Enterprise 3.1", "release_date": "2016-05-03T00:00:00Z"}], "bugzilla": {"description": "jenkins: Non-constant time comparison of CSRF crumbs (SECURITY-245)", "id": "1311949", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1311949"}, "csaw": false, "cvss": {"cvss_base_score": "3.6", "cvss_scoring_vector": "AV:N/AC:H/Au:S/C:P/I:P/A:N", "status": "verified"}, "details": ["Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify CSRF tokens, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force approach."], "name": "CVE-2016-0791", "public_date": "2016-02-24T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2016-0791\nhttps://nvd.nist.gov/vuln/detail/CVE-2016-0791\nhttps://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-02-24"], "threat_severity": "Moderate"}