[MAVEN:GHSA-M82G-FV7V-H64M] Jenkins Sonar Gerrit Plugin vulnerable to Cross-Site Request Forgery

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

A cross-site request forgery (CSRF) vulnerability in Jenkins Sonar Gerrit Plugin 377.v8f3808963dc5 and earlier allows attackers to have Jenkins connect to Gerrit servers (previously configured by Jenkins administrators) using attacker-specified credentials IDs obtained through another method, potentially capturing credentials stored in Jenkins.

Package Affected Version
pkg:maven/org.jenkins-ci.plugins/sonar-gerrit <= 377.v8f3808963dc5
Package Fixed Version
pkg:maven/org.jenkins-ci.plugins/sonar-gerrit = 378.vf4646d4df087
ID
MAVEN:GHSA-M82G-FV7V-H64M
Severity
moderate
URL
https://github.com/advisories/GHSA-m82g-fv7v-h64m
Published
2022-12-12T09:30:35
(21 months ago)
Modified
2024-01-05T13:39:35
(8 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/sonar-gerrit org.jenkins-ci.plugins sonar-gerrit <= 377.v8f3808963dc5
Fixed pkg:maven/org.jenkins-ci.plugins/sonar-gerrit org.jenkins-ci.plugins sonar-gerrit = 378.vf4646d4df087
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...