GHSA-xc7q-p3f4-q389
Dashboard / Vulnerabilities / GHSA-xc7q-p3f4-q389
Summary: Jenkins Project Inheritance Plugin vulnerable to Cross-Site Request Forgery
Details: Project Inheritance Plugin allows the creation of projects based on templates defined in the plugin configuration. A missing permission check in the HTTP endpoint triggering project creation allowed users with Overall/Read permission to create these projects. Additionally, the HTTP endpoint did not require POST requests, resulting in a CSRF vulnerability. The HTTP endpoint triggering project creation now requires Item/Create permission and submission of requests via POST.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-10408, https://jenkins.io/security/advisory/2019-09-25/#SECURITY-401, http://www.openwall.com/lists/oss-security/2019/09/25/3
Affected packages
Package
Name: hudson.plugins:project-inheritance
Purl: pkg:maven/hudson.plugins/project-inheritance
Affected ranges
Type: ECOSYSTEM
Events:
