Vulnerability GHSA-9cfq-v2hm-c3xr

Medium Risk
MEDIUM RISK
CVSS Score: 4.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
4 years ago
May 14, 2022 at 03:13 AM UTC
Jenkins GitHub Branch Source Plugin vulnerable to Server-Side Request Forgery
1.0.0 - 1.10.1
1.0.0 - 1.10.1

Summary

Jenkins GitHub Branch Source Plugin vulnerable to Server-Side Request Forgery

Details

A server-side request forgery vulnerability exists in Jenkins GitHub Branch Source Plugin 2.3.4 and older in Endpoint.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL. Additionally, this form validation method did not require POST requests, resulting in a CSRF vulnerability. As of version 23.5, this form validation method requires POST requests and the Overall/Administer permission.

Timeline

Published
4 years ago
May 14, 2022 at 03:13 AM UTC
Last Modified
2 years ago
February 16, 2024 at 08:22 AM UTC