VDB
EN
MEDIUM 5.4

GHSA-7g95-jmg9-h524

Jenkins cross-site request forgery (CSRF) vulnerability

빠른 조치

GHSA-7g95-jmg9-h524 — org.jenkins-ci.main:jenkins-core: 아래 명령으로 수정 버전으로 올리세요.

# pom.xml: bump <version>2.500</version> for org.jenkins-ci.main:jenkins-core

상세

Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not require POST requests for the HTTP endpoint toggling collapsed/expanded status of sidepanel widgets (e.g., Build Queue and Build Executor Status widgets), resulting in a cross-site request forgery (CSRF) vulnerability.

This vulnerability allows attackers to have users toggle their collapsed/expanded status of sidepanel widgets.

Additionally, as the API accepts any string as the identifier of the panel ID to be toggled, attacker-controlled content can be stored in the victim’s user profile in Jenkins.

Jenkins 2.500, LTS 2.492.2 requires POST requests for the affected HTTP endpoint.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

Maven / org.jenkins-ci.main:jenkins-core
최초 영향 버전: 2.493 수정 버전: 2.500
수정 # pom.xml: bump <version>2.500</version> for org.jenkins-ci.main:jenkins-core
Maven / org.jenkins-ci.main:jenkins-core
최초 영향 버전: 0 수정 버전: 2.492.2
수정 # pom.xml: bump <version>2.492.2</version> for org.jenkins-ci.main:jenkins-core

참고