Cross-Site Request Forgery in Jenkins OpenShift Deployer Plugin
CVE-2019-1003080
6.5MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 4 April 2019
What is CVE-2019-1003080?
The Jenkins OpenShift Deployer Plugin is vulnerable to a cross-site request forgery (CSRF) flaw. This vulnerability arises from improper validation in the DeployApplicationDescriptor#doCheckLogin method, allowing attackers to initiate server connections to locations specified by them. Exploiting this vulnerability could enable unauthorized actions to be performed on behalf of an authenticated user without their consent.
Affected Version(s)
Jenkins OpenShift Deployer Plugin all versions as of 2019-04-03