GHSA-whf8-3h58-2w9f
Dashboard / Vulnerabilities / GHSA-whf8-3h58-2w9f
Summary: Jenkins Warnings Next Generation Plugin cross-site request forgery vulnerability
Details: Jenkins Warnings Next Generation Plugin has a form validation HTTP endpoint used to validate a Groovy script through compilation, which was not subject to sandbox protection. The endpoint checked for the Overall/RunScripts permission, but did not require POST requests, so it was vulnerable to cross-site request forgery (CSRF). This allowed attackers to execute arbitrary code on the Jenkins controller by applying AST transforming annotations such as `@Grab` to source code elements. The affected HTTP endpoint now applies a safe Groovy compiler configuration preventing the use of unsafe AST transforming annotations. Additionally, the form validation HTTP endpoint now requires that requests be sent via POST to prevent CSRF.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-1003008, https://jenkins.io/security/advisory/2019-01-28/#SECURITY-1295%20(2)
Affected packages
Package
Name: io.jenkins.plugins:warnings-ng
Purl: pkg:maven/io.jenkins.plugins/warnings-ng
Affected ranges
Type: ECOSYSTEM
Events:
