Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Xingyunyang

#40253de 53,635
6.8CVSS total
Vulnerabilidades · 1
PT-2019-11764
6.8
2019-08-07
Jenkins · Jenkins Jclouds Plugin · CVE-2019-10368
**Name of the Vulnerable Software and Affected Versions** Jenkins JClouds Plugin versions 2.14 and earlier **Description** A cross-site request forgery issue allows users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs, potentially capturing credentials stored in Jenkins. The vulnerability is due to a lack of permission checks on a form validation method, which also did not require POST requests. **Recommendations** For Jenkins JClouds Plugin versions 2.14 and earlier, update the plugin to a version that requires POST requests and Overall/Administer permission for the form validation method, thus preventing the cross-site request forgery vulnerability.