Cross-Site Request Forgery in Jenkins Rundeck Plugin
CVE-2019-10454

4.3MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
16 October 2019

Summary

A cross-site request forgery flaw exists in the Jenkins Rundeck Plugin, which permits attackers to forge requests that are sent to the server. This vulnerability enables attackers to use maliciously crafted links or forms to send requests using the credentials of authenticated users, allowing unauthorized access to an attacker-specified URL. This could lead to data exposure and potential compromise of user accounts.

Affected Version(s)

Jenkins Rundeck Plugin 3.6.5 and earlier

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.