Описание
CSRF vulnerability in Jenkins OpenShift Deployer Plugin
OpenShift Deployer Plugin 1.2.0 and earlier does not perform permission checks in methods implementing form validation.
These form validation methods do not require POST requests, resulting in a cross-site request forgery (CSRF) vulnerability.
Пакеты
org.jenkins-ci.plugins:openshift-deployer
<= 1.2.0
Отсутствует
Связанные уязвимости
A cross-site request forgery (CSRF) vulnerability in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers to check for the existence of an attacker-specified file path on the Jenkins controller file system and to upload a SSH key file from the Jenkins controller file system to an attacker-specified URL.
Уязвимость компонента Controller File System Handler плагина Jenkins OpenShift Deployer Plugin, позволяющая нарушителю выполнить произвольные действия на уязвимом устройстве