Lucene search

K
osvGoogleOSV:GHSA-5FRH-WX6V-8M2R
HistoryMay 24, 2022 - 7:06 p.m.

CSRF vulnerabilities in Jenkins requests-plugin Plugin

2022-05-2419:06:36
Google
osv.dev
6

0.001 Low

EPSS

Percentile

25.4%

Jenkins requests-plugin Plugin 2.2.12 and earlier does not require POST requests to request and apply changes, resulting in cross-site request forgery (CSRF) vulnerabilities.

These vulnerabilities allow attackers to create requests and/or have administrators apply pending requests, like renaming or deleting jobs, deleting builds, etc.

Jenkins requests-plugin Plugin 2.2.13 requires POST requests for the affected HTTP endpoints. This was partially fixed in requests-plugin Plugin 2.2.8 to require POST requests for some of the affected HTTP endpoints, but the endpoint allowing administrators to apply pending requests remained unprotected until 2.2.13.

0.001 Low

EPSS

Percentile

25.4%

Related for OSV:GHSA-5FRH-WX6V-8M2R