Cross-Site Request Forgery in the Jenkins Claim plugin
Moderate severity
GitHub Reviewed
Published
Jun 16, 2021
to the GitHub Advisory Database
•
Updated Oct 27, 2023
Description
Published by the National Vulnerability Database
Feb 24, 2021
Reviewed
May 7, 2021
Published to the GitHub Advisory Database
Jun 16, 2021
Last updated
Oct 27, 2023
Jenkins Claim Plugin 2.18.1 and earlier does not require POST requests for the form submission endpoint assigning claims, resulting in a cross-site request forgery (CSRF) vulnerability.
This vulnerability allows attackers to change claims.
Jenkins Claim Plugin 2.18.2 requires POST requests for the affected HTTP endpoint.
References