Cross-Site Request Forgery in Jenkins Project Inheritance Plugin
CVE-2019-10408
4.3MEDIUM
Summary
The Jenkins Project Inheritance Plugin before version 2.0.0 is susceptible to a cross-site request forgery (CSRF) vulnerability that enables attackers to initiate project generation from existing templates without proper authorization. This flaw could potentially allow malicious users to execute unintended actions within Jenkins, leading to unauthorized alterations in project configurations.
Affected Version(s)
Jenkins Project Inheritance Plugin 2.0.0 and earlier
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved