[JENKINS:SECURITY-2762] CSRF vulnerability in `external-monitor-job`

Severity Medium
Affected Packages 2
Fixed Packages 2
CVEs 1

external-monitor-job 191.v363d0d1efdf8 and earlier does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery (CSRF) vulnerability.

This vulnerability allows attackers to create runs of an external job.

external-monitor-job 192.ve979ca_8b_3ccd requires POST requests for the affected HTTP endpoint.

ID
JENKINS:SECURITY-2762
Severity
medium
Published
2022-07-27T00:00:00
(2 years ago)
Modified
2022-07-27T00:00:00
(2 years ago)
Rights
Jenkins Security Team
Other Advisories
Source # ID Name URL
Plugin repository external-monitor-job repository https://github.com/jenkinsci/external-monitor-job-plugin
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/external-monitor-job org.jenkins-ci.plugins external-monitor-job <= 191.v363d0d1efdf8
Fixed pkg:maven/org.jenkins-ci.plugins/external-monitor-job org.jenkins-ci.plugins external-monitor-job = 192.ve979ca_8b_3ccd
Affected pkg:github/jenkinsci/external-monitor-job-plugin jenkinsci external-monitor-job-plugin <= 191.v363d0d1efdf8
Fixed pkg:github/jenkinsci/external-monitor-job-plugin jenkinsci external-monitor-job-plugin = 192.ve979ca_8b_3ccd
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...