Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g975-f26h-93g8

Опубликовано: 19 окт. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8

Описание

Jenkins Pipeline: Stage View Plugin allows CSRF protection bypass of any target URL in Jenkins

Jenkins Pipeline: Stage View Plugin provides a visualization of Pipeline builds. It also allows users to interact with input steps from Pipeline: Input Step Plugin.

Pipeline: Stage View Plugin 2.26 and earlier does not correctly encode the ID of input steps when using it to generate URLs to proceed or abort Pipeline builds.

This allows attackers able to configure Pipelines to specify input step IDs resulting in URLs that would bypass the CSRF protection of any target URL in Jenkins.

Pipeline: Stage View Plugin 2.27 correctly encodes the ID of input steps when using it to generate URLs to proceed or abort Pipeline builds.

Пакеты

Наименование

org.jenkins-ci.plugins.pipeline-stage-view:pipeline-stage-view

maven
Затронутые версииВерсия исправления

>= 2.25, < 2.27

2.27

Наименование

org.jenkins-ci.plugins.pipeline-stage-view:pipeline-stage-view

maven
Затронутые версииВерсия исправления

< 2.24.2

2.24.2

EPSS

Процентиль: 1%
0.0001
Низкий

8 High

CVSS3

Дефекты

CWE-352
CWE-838

Связанные уязвимости

CVSS3: 5.7
redhat
больше 3 лет назад

Jenkins Pipeline: Stage View Plugin 2.26 and earlier does not correctly encode the ID of 'input' steps when using it to generate URLs to proceed or abort Pipeline builds, allowing attackers able to configure Pipelines to specify 'input' step IDs resulting in URLs that would bypass the CSRF protection of any target URL in Jenkins.

CVSS3: 6.5
nvd
больше 3 лет назад

Jenkins Pipeline: Stage View Plugin 2.26 and earlier does not correctly encode the ID of 'input' steps when using it to generate URLs to proceed or abort Pipeline builds, allowing attackers able to configure Pipelines to specify 'input' step IDs resulting in URLs that would bypass the CSRF protection of any target URL in Jenkins.

EPSS

Процентиль: 1%
0.0001
Низкий

8 High

CVSS3

Дефекты

CWE-352
CWE-838