Lucene search

K
osvGoogleOSV:GHSA-998M-F2X3-JJQ4
HistoryMay 24, 2022 - 5:48 p.m.

CSRF vulnerability in Jenkins Config File Provider Plugin allows deleting configuration files

2022-05-2417:48:05
Google
osv.dev
10

5.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.7%

Jenkins Config File Provider Plugin 3.7.0 and earlier does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery (CSRF) vulnerability.

This vulnerability allows attackers to delete configuration files corresponding to an attacker-specified ID.

This is due to an incomplete fix of SECURITY-938.

Jenkins Config File Provider Plugin 3.7.1 requires POST requests for the affected HTTP endpoint.

5.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.7%