Lucene search

K
osvGoogleOSV:GHSA-4FFQ-6G62-J4V4
HistoryJun 16, 2021 - 5:29 p.m.

Cross-Site Request Forgery in the Jenkins Claim plugin

2021-06-1617:29:43
Google
osv.dev
8

4.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.8%

Jenkins Claim Plugin 2.18.1 and earlier does not require POST requests for the form submission endpoint assigning claims, resulting in a cross-site request forgery (CSRF) vulnerability.

This vulnerability allows attackers to change claims.

Jenkins Claim Plugin 2.18.2 requires POST requests for the affected HTTP endpoint.

4.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.8%

Related for OSV:GHSA-4FFQ-6G62-J4V4