Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-21644

Опубликовано: 21 апр. 2021
Источник: redhat
CVSS3: 6.3
EPSS Низкий

Описание

A cross-site request forgery (CSRF) vulnerability in Jenkins Config File Provider Plugin 3.7.0 and earlier allows attackers to delete configuration files corresponding to an attacker-specified ID.

A cross-site request forgery (CSRF) vulnerability was found in the config-file-provider Jenkins plugin. The plugin does not require POST requests for an HTTP endpoint which allows attackers to delete configuration files corresponding to an attacker-specified ID.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-352
https://bugzilla.redhat.com/show_bug.cgi?id=1952151jenkins-2-plugins/config-file-provider: does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery (CSRF) vulnerability.

EPSS

Процентиль: 42%
0.00203
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
почти 5 лет назад

A cross-site request forgery (CSRF) vulnerability in Jenkins Config File Provider Plugin 3.7.0 and earlier allows attackers to delete configuration files corresponding to an attacker-specified ID.

CVSS3: 5.4
github
больше 3 лет назад

CSRF vulnerability in Jenkins Config File Provider Plugin allows deleting configuration files

EPSS

Процентиль: 42%
0.00203
Низкий

6.3 Medium

CVSS3