Jenkins Pipeline restFul API Plugin vulnerable to Cross Site Request Forgery
Discription

Jenkins Pipeline restFul API Plugin 0.11 and earlier does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery (CSRF) vulnerability.

This vulnerability allows attackers to have Jenkins connect to an attacker-specified URL, capturing a newly generated JCLI token that allows impersonating the victim.Read More

Back to Main

Subscribe for the latest news: