GHSA-3v9f-4vff-rx42

    Dashboard / Vulnerabilities / GHSA-3v9f-4vff-rx42

    GHSA-3v9f-4vff-rx42

    Published: 24 May 2022Last Modified: 16 Feb 2024

    Summary: Jenkins Static Analysis Utilities Plugin is vulnerable to Cross-site request forgery vulnerability

    Details: Jenkins analysis-core Plugin has the capability to allow other plugins to display trend graphs for their static analysis results. analysis-core Plugin provides the configuration form for the default settings of each graph. The configuration form and form submission handler did not perform a permission check, allowing attackers with Job/Read access to change the per-job graph configuration defaults for all users. Additionally, the form submission handler did not require POST requests, resulting in a cross-site request forgery vulnerability. analysis-core Plugin now requires Job/Configure permission and POST requests to configure the per-job graph defaults for all users.

    Affected packages

    Package

    Name: org.jvnet.hudson.plugins:analysis-core

    Purl: pkg:maven/org.jvnet.hudson.plugins/analysis-core

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.96

    Affected versions

    1.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-3v9f-4vff-rx42 | CVE-DB