Описание
Jenkins Vulnerable to Cross-Site Request Forgery (CSRF) Attack
Jenkins before 1.640 and LTS before 1.625.2 allow remote attackers to bypass the CSRF protection mechanism via unspecified vectors.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2015-7538
- https://github.com/jenkinsci/jenkins/commit/ba747888108d0db90d469c6d210b1df465d8fac1
- https://github.com/jenkinsci/jenkins/commit/ef2c0dc163695af3a57ad7a45571293377ff679b
- https://access.redhat.com/errata/RHSA-2016:0070
- https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-12-09
- http://rhn.redhat.com/errata/RHSA-2016-0489.html
Пакеты
org.jenkins-ci.main:jenkins-core
>= 1.626, < 1.640
1.640
org.jenkins-ci.main:jenkins-core
< 1.625.2
1.625.2
Связанные уязвимости
Jenkins before 1.640 and LTS before 1.625.2 allow remote attackers to bypass the CSRF protection mechanism via unspecified vectors.
Jenkins before 1.640 and LTS before 1.625.2 allow remote attackers to bypass the CSRF protection mechanism via unspecified vectors.
Jenkins before 1.640 and LTS before 1.625.2 allow remote attackers to bypass the CSRF protection mechanism via unspecified vectors.
Jenkins before 1.640 and LTS before 1.625.2 allow remote attackers to ...