Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3vhr-f5xr-8vpx

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Jenkins Vulnerable to Cross-Site Request Forgery (CSRF) Attack

Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via vectors related to the HTTP GET method.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 1.626, < 1.640

1.640

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

< 1.625.2

1.625.2

EPSS

Процентиль: 60%
0.00397
Низкий

8.8 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 10 лет назад

Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via vectors related to the HTTP GET method.

redhat
около 10 лет назад

Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via vectors related to the HTTP GET method.

CVSS3: 8.8
nvd
около 10 лет назад

Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via vectors related to the HTTP GET method.

CVSS3: 8.8
debian
около 10 лет назад

Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.64 ...

EPSS

Процентиль: 60%
0.00397
Низкий

8.8 High

CVSS3

Дефекты

CWE-352