Lucene search

K
osvGoogleOSV:GHSA-PHWV-CRGP-9R69
HistoryMay 24, 2022 - 4:44 p.m.

Jenkins GitHub Authentication Plugin Cross-Site Request Forgery vulnerability

2022-05-2416:44:55
Google
osv.dev
4

6.9 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

68.1%

Jenkins GitHub Authentication Plugin did not manage the state parameter of OAuth to prevent CSRF. This allowed an attacker to catch the redirect URL provided during the authentication process using OAuth and send it to the victim. If the victim was already connected to Jenkins, their Jenkins account would be attached to the attacker’s GitHub account.

The state parameter is now correctly managed.

6.9 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

68.1%

Related for OSV:GHSA-PHWV-CRGP-9R69