Lucene search

K
nvd[email protected]NVD:CVE-2024-2215
HistoryMar 06, 2024 - 5:15 p.m.

CVE-2024-2215

2024-03-0617:15:11
web.nvd.nist.gov
cve-2024-2215
cross-site request forgery
jenkins
docker-build-step plugin
tcp
unix socket url
reconfigure
connection test parameters
build step executions

0.0004 Low

EPSS

Percentile

9.1%

A cross-site request forgery (CSRF) vulnerability in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test parameters, affecting future build step executions.

0.0004 Low

EPSS

Percentile

9.1%