Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-35141

Опубликовано: 14 июн. 2023
Источник: redhat
CVSS3: 8
EPSS Низкий

Описание

In Jenkins 2.399 and earlier, LTS 2.387.3 and earlier, POST requests are sent in order to load the list of context actions. If part of the URL includes insufficiently escaped user-provided values, a victim may be tricked into sending a POST request to an unexpected endpoint by opening a context menu.

A flaw was found in Jenkins and Jenkins Long-Term Support (LTS), where it could allow a remote, authenticated attacker to bypass security restrictions caused by the inclusion of insufficiently escaped user-provided values in part of the URL. An attacker can send a POST request to an unexpected endpoint by persuading a victim to open a context menu.

Отчет

OpenShift 3.11 is in ELS. Jenkins and its related technologies will not be supported under ELS. Hence, OpenShift 3.11 is marked as affected/won'tfix.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 2jenkinsNot affected
Node HealthCheck OperatorjenkinsNot affected
OpenShift Developer Tools and ServicesjenkinsNot affected
Red Hat OpenShift Container Platform 3.11jenkinsWill not fix
Red Hat OpenShift Container Platform 4jenkinsAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-352
https://bugzilla.redhat.com/show_bug.cgi?id=2215074jenkins: CSRF protection bypass vulnerability

EPSS

Процентиль: 26%
0.00092
Низкий

8 High

CVSS3

Связанные уязвимости

CVSS3: 8
nvd
больше 2 лет назад

In Jenkins 2.399 and earlier, LTS 2.387.3 and earlier, POST requests are sent in order to load the list of context actions. If part of the URL includes insufficiently escaped user-provided values, a victim may be tricked into sending a POST request to an unexpected endpoint by opening a context menu.

CVSS3: 8
debian
больше 2 лет назад

In Jenkins 2.399 and earlier, LTS 2.387.3 and earlier, POST requests a ...

CVSS3: 8
github
больше 2 лет назад

Jenkins CSRF protection bypass vulnerability

EPSS

Процентиль: 26%
0.00092
Низкий

8 High

CVSS3