Cross-Site Request Forgery in Jenkins Project Inheritance Plugin
CVE-2019-10408

4.3MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
25 September 2019

Summary

The Jenkins Project Inheritance Plugin before version 2.0.0 is susceptible to a cross-site request forgery (CSRF) vulnerability that enables attackers to initiate project generation from existing templates without proper authorization. This flaw could potentially allow malicious users to execute unintended actions within Jenkins, leading to unauthorized alterations in project configurations.

Affected Version(s)

Jenkins Project Inheritance Plugin 2.0.0 and earlier

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.