[MAVEN:GHSA-26J3-4M55-J6R7] Jenkins Azure VM Agents Plugin Cross-site Request Forgery vulnerability

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier does not perform permission checks in several HTTP endpoints.

This allows attackers with Overall/Read permission to connect to an attacker-specified Azure Cloud server using attacker-specified credentials IDs obtained through another method.

Additionally, these HTTP endpoints do not require POST requests, resulting in a cross-site request forgery (CSRF) vulnerability.

Azure VM Agents Plugin 853.v4a_1a_dd947520 requires POST requests and the appropriate permissions for the affected HTTP endpoints.

Package Affected Version
pkg:maven/org.jenkins-ci.plugins/azure-vm-agents < 853.v4a
Package Fixed Version
pkg:maven/org.jenkins-ci.plugins/azure-vm-agents = 853.v4a
ID
MAVEN:GHSA-26J3-4M55-J6R7
Severity
moderate
URL
https://github.com/advisories/GHSA-26j3-4m55-j6r7
Published
2023-05-16T18:30:16
(16 months ago)
Modified
2023-11-06T05:05:52
(10 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/azure-vm-agents org.jenkins-ci.plugins azure-vm-agents < 853.v4a
Fixed pkg:maven/org.jenkins-ci.plugins/azure-vm-agents org.jenkins-ci.plugins azure-vm-agents = 853.v4a
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...