Cross-Site Request Forgery in Jenkins Rundeck Plugin
CVE-2019-10454
4.3MEDIUM
Summary
A cross-site request forgery flaw exists in the Jenkins Rundeck Plugin, which permits attackers to forge requests that are sent to the server. This vulnerability enables attackers to use maliciously crafted links or forms to send requests using the credentials of authenticated users, allowing unauthorized access to an attacker-specified URL. This could lead to data exposure and potential compromise of user accounts.
Affected Version(s)
Jenkins Rundeck Plugin 3.6.5 and earlier
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved