Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45839
HistoryMar 12, 2024 - 6:32 a.m.

Cross Site Request Forgery (CSRF)

2024-03-1206:32:11
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
cross site request forgery
jenkins
docker
validation
user inputs
tcp
unix socket url
reconfigure
plugin
build step
executions
vulnerability

AI Score

6.8

Confidence

High

EPSS

0

Percentile

9.0%

org.jenkins-ci.plugins: docker-build-step is vulnerable to Cross Site Request Forgery (CSRF). The vulnerability is due to inadequate validation of user inputs, allowing attackers to connect to an attacker-specified TCP or Unix socket URL and reconfigure the plugin using provided connection test parameters, impacting future build step executions.

AI Score

6.8

Confidence

High

EPSS

0

Percentile

9.0%