Lucene search

K
githubGitHub Advisory DatabaseGHSA-64C5-R2H5-C2FG
HistoryMar 06, 2024 - 6:30 p.m.

Jenkins docker-build-step Plugin Cross-Site Request Forgery vulnerability

2024-03-0618:30:39
CWE-352
GitHub Advisory Database
github.com
10
jenkins
docker-build-step
plugin
csrf
vulnerability
attackers
socket url
connection test parameters
build step executions

6.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

A cross-site request forgery (CSRF) vulnerability in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test parameters, affecting future build step executions.

Affected configurations

Vulners
Node
jenkinspipeline\Match_build_stepjenkins

6.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Related for GHSA-64C5-R2H5-C2FG