Lucene search

K
osvGoogleOSV:GHSA-RP4X-XPGF-4XV7
HistoryMay 24, 2022 - 5:19 p.m.

Complete lack of CSRF protection in Jenkins Selenium Plugin can lead to OS command injection

2022-05-2417:19:04
Google
osv.dev
4
jenkins
selenium plugin
csrf protection
os command injection
http endpoints
selenium grid hub
configuration parameters
jenkins controller

EPSS

0.002

Percentile

51.6%

Selenium Plugin 3.141.59 and earlier has no CSRF protection for its HTTP endpoints.

This allows attackers to perform the following actions:

  • Restart the Selenium Grid hub.
  • Delete or replace the plugin configuration.
  • Start, stop, or restart Selenium configurations on specific nodes.

Through carefully chosen configuration parameters, these actions can result in OS command injection on the Jenkins controller.

EPSS

0.002

Percentile

51.6%

Related for OSV:GHSA-RP4X-XPGF-4XV7