Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p92q-7fhh-mq35

Опубликовано: 21 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Cross-Site Request Forgery in Jenkins

Jenkins 2.329 and earlier, LTS 2.319.1 and earlier does not require POST requests for the HTTP endpoint handling manual build requests when no security realm is set, resulting in a cross-site request forgery (CSRF) vulnerability.

This vulnerability allows attackers to trigger build of job without parameters.

Jenkins 2.330, LTS 2.319.2 requires POST requests for the affected HTTP endpoint.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.320, < 2.330

2.330

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

< 2.319.2

2.319.2

EPSS

Процентиль: 42%
0.002
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 4 лет назад

A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and earlier, LTS 2.319.1 and earlier allows attackers to trigger build of job without parameters when no security realm is set.

CVSS3: 4.3
redhat
около 4 лет назад

A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and earlier, LTS 2.319.1 and earlier allows attackers to trigger build of job without parameters when no security realm is set.

CVSS3: 4.3
nvd
около 4 лет назад

A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and earlier, LTS 2.319.1 and earlier allows attackers to trigger build of job without parameters when no security realm is set.

CVSS3: 4.3
debian
около 4 лет назад

A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and ...

EPSS

Процентиль: 42%
0.002
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-352