PT-2018-15217 · Jenkins · Jenkins Publisher Over Cifs Plugin+1

Viktor Gazdag

·

Publicado

2018-08-01

·

Atualizado

2022-05-14

·

CVE-2018-1999038

CVSS v2.0

4.9

Média

VetorAV:N/AC:M/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Publisher Over CIFS Plugin versions 0.10 and earlier
Description A confused deputy issue exists that allows attackers to have Jenkins connect to an attacker-specified CIFS server with attacker-specified credentials. Additionally, a CSRF issue is present due to a form validation method not requiring POST requests.
Recommendations For Jenkins Publisher Over CIFS Plugin versions 0.10 and earlier, update to version 0.11 or later, which requires POST requests and Overall/Administer permissions for the form validation method, addressing both the confused deputy and CSRF issues.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1999038
GHSA-RF7H-9M85-535V

Produtos afetados

Jenkins
Jenkins Publisher Over Cifs Plugin