PT-2019-14703 · Jenkins · Jenkins Google Compute Engine Plugin+1
Matt Sicker
·
Publicado
2019-11-21
·
Atualizado
2023-10-25
·
CVE-2019-16548
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Jenkins Google Compute Engine Plugin versions 4.1.1 and earlier
Description
A cross-site request forgery issue exists in the ComputeEngineCloud#doProvision function, which could be used to provision new agents. The Google Compute Engine Plugin version 4.2.0 mitigates this by requiring POST requests for the affected API endpoint.
Recommendations
For Jenkins Google Compute Engine Plugin versions 4.1.1 and earlier, consider updating to version 4.2.0 or later, which requires POST requests for the affected API endpoint, to prevent cross-site request forgery attacks. As a temporary workaround, consider restricting access to the ComputeEngineCloud#doProvision function until a patch is available.
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Jenkins
Jenkins Google Compute Engine Plugin