Lucene search

K
osvGoogleOSV:GHSA-2WF5-4MF7-VMH3
HistoryMay 24, 2022 - 5:33 p.m.

CSRF vulnerability in Jenkins Active Directory Plugin

2022-05-2417:33:07
Google
osv.dev
10
jenkins
active directory
csrf
vulnerability
connection tests

AI Score

4.8

Confidence

High

EPSS

0.001

Percentile

26.7%

Jenkins Active Directory Plugin 2.19 and earlier does not require POST requests for multiple HTTP endpoints implementing connection and authentication tests, resulting in cross-site request forgery (CSRF) vulnerabilities.

This vulnerability allows attackers to perform connection tests, connecting to attacker-specified or previously configured Active Directory servers using attacker-specified credentials.

Active Directory Plugin 2.20 requires POST requests for the affected HTTP endpoints.

AI Score

4.8

Confidence

High

EPSS

0.001

Percentile

26.7%

Related for OSV:GHSA-2WF5-4MF7-VMH3