Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1000411

Опубликовано: 25 сент. 2018
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

A cross-site request forgery vulnerability exists in Jenkins JUnit Plugin 1.25 and earlier in TestObject.java that allows setting the description of a test result.

Отчет

For Openshift, Jenkins is used within the infrastructure and deployment in OCP. The package is delivered within the technology but not used by default in production environments. It requires additional configuration in running environments which would be mainly use on testing applications being deployed. The update is in the latest version released with Red Hat OpenShift 3.11.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.10jenkins-2-pluginsWill not fix
Red Hat OpenShift Container Platform 3.11jenkins-2-pluginsWill not fix
Red Hat OpenShift Container Platform 3.3jenkins-plugin-junitWill not fix
Red Hat OpenShift Container Platform 3.4jenkins-plugin-junitWill not fix
Red Hat OpenShift Container Platform 3.5jenkins-plugin-junitWill not fix
Red Hat OpenShift Container Platform 3.6jenkins-2-pluginsWill not fix
Red Hat OpenShift Container Platform 3.7jenkins-2-pluginsWill not fix
Red Hat OpenShift Container Platform 3.9jenkins-2-pluginsWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-352
https://bugzilla.redhat.com/show_bug.cgi?id=1639388jenkins-plugin-junit: CSRF due to URL not requiring POST requests

EPSS

Процентиль: 59%
0.00385
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
около 7 лет назад

A cross-site request forgery vulnerability exists in Jenkins JUnit Plugin 1.25 and earlier in TestObject.java that allows setting the description of a test result.

CVSS3: 6.5
github
больше 3 лет назад

Jenkins JUnit Plugin CSRF vulnerability

EPSS

Процентиль: 59%
0.00385
Низкий

4.3 Medium

CVSS3