VDB
Sign up
MEDIUM4.3

GHSA-fq56-wvv2-p8jf

Jenkins Priority Sorter Plugin has a CSRF vulnerability

Quick fix

GHSA-fq56-wvv2-p8jf — org.jenkins-ci.plugins:PrioritySorter: upgrade to the fixed version with the command below.

# pom.xml: bump <version>936.937.v5581d0b</version> for org.jenkins-ci.plugins:PrioritySorter

Details

Jenkins Priority Sorter Plugin 936.v2c01c6b_84449 and earlier does not require POST requests in an HTTP endpoint that saves the global job priority configuration.

This allows attackers to overwrite the global job priority configuration.

Priority Sorter Plugin 936.937.v5581d0b_2ccb_a_ requires POST requests for the affected HTTP endpoint.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.jenkins-ci.plugins:PrioritySorter
Introduced in: 0Fixed in: 936.937.v5581d0b
Fix# pom.xml: bump <version>936.937.v5581d0b</version> for org.jenkins-ci.plugins:PrioritySorter

References