Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xc7q-p3f4-q389

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Jenkins Project Inheritance Plugin vulnerable to Cross-Site Request Forgery

Project Inheritance Plugin allows the creation of projects based on templates defined in the plugin configuration.

A missing permission check in the HTTP endpoint triggering project creation allowed users with Overall/Read permission to create these projects. Additionally, the HTTP endpoint did not require POST requests, resulting in a CSRF vulnerability.

The HTTP endpoint triggering project creation now requires Item/Create permission and submission of requests via POST.

Пакеты

Наименование

hudson.plugins:project-inheritance

maven
Затронутые версииВерсия исправления

< 19.08.2

19.08.2

EPSS

Процентиль: 59%
0.00377
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 4.3
nvd
больше 6 лет назад

A cross-site request forgery vulnerability in Jenkins Project Inheritance Plugin 2.0.0 and earlier allowed attackers to trigger project generation from templates.

EPSS

Процентиль: 59%
0.00377
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-352