PT-2019-14703 · Jenkins · Jenkins Google Compute Engine Plugin+1

Matt Sicker

·

Publicado

2019-11-21

·

Atualizado

2023-10-25

·

CVE-2019-16548

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Jenkins Google Compute Engine Plugin versions 4.1.1 and earlier
Description A cross-site request forgery issue exists in the ComputeEngineCloud#doProvision function, which could be used to provision new agents. The Google Compute Engine Plugin version 4.2.0 mitigates this by requiring POST requests for the affected API endpoint.
Recommendations For Jenkins Google Compute Engine Plugin versions 4.1.1 and earlier, consider updating to version 4.2.0 or later, which requires POST requests for the affected API endpoint, to prevent cross-site request forgery attacks. As a temporary workaround, consider restricting access to the ComputeEngineCloud#doProvision function until a patch is available.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-16548
GHSA-X24M-WR2F-P3VC

Produtos afetados

Jenkins
Jenkins Google Compute Engine Plugin