GHSA-99hj-ppg3-2xwc

    Dashboard / Vulnerabilities / GHSA-99hj-ppg3-2xwc

    GHSA-99hj-ppg3-2xwc

    Published: 14 May 2022Last Modified: 4 Mar 2024

    Summary: Cross-Site Request Forgery in Jenkins

    Details: A race condition during Jenkins 2.94 and earlier; 2.89.1 and earlier startup could result in the wrong order of execution of commands during initialization. There is a very short window of time after startup during which Jenkins may no longer show the 'Please wait while Jenkins is getting ready to work' message but Cross-Site Request Forgery (CSRF) protection may not yet be effective.

    Affected packages

    Package

    Name: org.jenkins-ci.main:jenkins-core

    Purl: pkg:maven/org.jenkins-ci.main/jenkins-core

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 2.81
    Fixed -2.89.2

    Affected versions

    2.81

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-99hj-ppg3-2xwc | CVE-DB