Lucene search

K
osvGoogleOSV:GHSA-VX6R-W45X-Q3H6
HistoryMay 24, 2022 - 4:59 p.m.

Jenkins Kubernetes CI/CD Plugin vulnerable to Cross-Site Request Forgery

2022-05-2416:59:37
Google
osv.dev
3

0.001 Low

EPSS

Percentile

33.0%

A cross-site request forgery vulnerability in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

Note: Jenkins has suspended distribution of this plugin.

0.001 Low

EPSS

Percentile

33.0%

Related for OSV:GHSA-VX6R-W45X-Q3H6