Описание
A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and earlier, LTS 2.319.1 and earlier allows attackers to trigger build of job without parameters when no security realm is set.
A Cross-site request forgery (CSRF) vulnerability was found in Jenkins. The POST requests are not required for the HTTP endpoint handling manual build requests when no security realm is set. This flaw allows an attacker to trigger the building of a job without parameters.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Fuse 7 | jenkins | Not affected | ||
| Red Hat OpenShift Container Platform 3.11 | jenkins | Fixed | RHSA-2022:0555 | 24.02.2022 |
| Red Hat OpenShift Container Platform 4.6 | jenkins | Fixed | RHSA-2022:0565 | 25.02.2022 |
| Red Hat OpenShift Container Platform 4.7 | jenkins | Fixed | RHSA-2022:0491 | 16.02.2022 |
| Red Hat OpenShift Container Platform 4.8 | jenkins | Fixed | RHSA-2022:0483 | 16.02.2022 |
| Red Hat OpenShift Container Platform 4.9 | jenkins | Fixed | RHSA-2022:0339 | 10.02.2022 |
Показывать по
Дополнительная информация
Статус:
4.3 Medium
CVSS3
Связанные уязвимости
A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and earlier, LTS 2.319.1 and earlier allows attackers to trigger build of job without parameters when no security realm is set.
A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and earlier, LTS 2.319.1 and earlier allows attackers to trigger build of job without parameters when no security realm is set.
A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and ...
4.3 Medium
CVSS3