Описание
A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and earlier, LTS 2.319.1 and earlier allows attackers to trigger build of job without parameters when no security realm is set.
Ссылки
- Mailing ListThird Party Advisory
- Vendor Advisory
- PatchThird Party Advisory
- Mailing ListThird Party Advisory
- Vendor Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.319.1 (включая)Версия до 2.329 (включая)
Одно из
cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*
cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*
Конфигурация 2
cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.9.0:*:*:*:*:*:*:*
EPSS
Процентиль: 39%
0.00173
Низкий
4.3 Medium
CVSS3
2.6 Low
CVSS2
Дефекты
CWE-352
Связанные уязвимости
CVSS3: 4.3
ubuntu
около 4 лет назад
A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and earlier, LTS 2.319.1 and earlier allows attackers to trigger build of job without parameters when no security realm is set.
CVSS3: 4.3
redhat
около 4 лет назад
A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and earlier, LTS 2.319.1 and earlier allows attackers to trigger build of job without parameters when no security realm is set.
CVSS3: 4.3
debian
около 4 лет назад
A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and ...
EPSS
Процентиль: 39%
0.00173
Низкий
4.3 Medium
CVSS3
2.6 Low
CVSS2
Дефекты
CWE-352