Cross-Site Request Forgery in Jenkins Plugin by CloudBees
CVE-2019-10278

6.5MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
4 April 2019

Summary

A cross-site request forgery vulnerability exists in the Jenkins jenkins-reviewbot Plugin that allows unauthorized attackers to exploit the ReviewboardDescriptor#doTestConnection method. This vulnerability can lead to attackers initiating connections to a server of their choice without user consent, creating potential privacy and security risks for affected users. It is crucial for plugin users to ensure they are using patched versions to mitigate any risks related to this vulnerability.

Affected Version(s)

Jenkins jenkins-reviewbot Plugin all versions as of 2019-04-03

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.