Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c264-8834-ppj2

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

CSRF vulnerability in Jenkins Swarm Plugin

Swarm Plugin adds API endpoints to add or remove agent labels. In Swarm Plugin 3.20 and earlier these only require a global Swarm secret to use, and no regular permission check is performed. This allows users with Agent/Create permission to add or remove labels of any agent.

Additionally, these API endpoints do not require POST requests, resulting in a cross-site request forgery (CSRF) vulnerability.

Swarm Plugin 3.21 requires POST requests and Agent/Configure permission for the affected agent to these endpoints. It no longer uses the global Swarm secret for these API endpoints.

Пакеты

Наименование

org.jenkins-ci.plugins:swarm

maven
Затронутые версииВерсия исправления

< 3.21

3.21

EPSS

Процентиль: 61%
0.00412
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 6.5
nvd
больше 5 лет назад

A cross-site request forgery vulnerability in Jenkins Self-Organizing Swarm Plug-in Modules Plugin 3.20 and earlier allows attackers to add or remove agent labels.

EPSS

Процентиль: 61%
0.00412
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-352