GHSA-5cxw-8v65-76vf

    Dashboard / Vulnerabilities / GHSA-5cxw-8v65-76vf

    GHSA-5cxw-8v65-76vf

    Published: 24 May 2022Last Modified: 16 Feb 2024

    Summary: CSRF vulnerability in Jenkins promoted builds Plugin

    Details: Jenkins promoted builds Plugin 3.9 and earlier does not require POST requests for HTTP endpoints implementing promotion (regular, forced, and re-execute), resulting in cross-site request forgery (CSRF) vulnerabilities. These vulnerabilities allow attackers to promote builds. Jenkins promoted builds Plugin 3.9.1 requires POST requests for the affected HTTP endpoints. A security hardening since Jenkins 2.287 and LTS 2.277.2 prevents exploitation of this vulnerability.

    Affected packages

    Package

    Name: org.jenkins-ci.plugins:promoted-builds

    Purl: pkg:maven/org.jenkins-ci.plugins/promoted-builds

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -3.9.1

    Affected versions

    2.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-5cxw-8v65-76vf | CVE-DB