MEDIUM✓ PATCH🇵🇱 Wersja polska

CVE-2019-1003098

CVSS 6.5v3.0pub. 2019-04-04upd. 2024-11-21

A cross-site request forgery vulnerability in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate form validation method allows attackers to initiate a connection to an attacker-specified server.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
  • Jenkins Openid

    APP
    Jenkins
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
CI/CD
CWE
References

Related vulnerabilities

CVE-2023-24444CRITICAL9.8PL ✓same product

Jenkins OpenID Plugin: brak unieważnienia sesji przy logowaniu

CVE-2023-24446HIGH8.8same product

A cross-site request forgery (CSRF) vulnerability in Jenkins OpenID Plugin 2.4 and earlier allows attackers to...

CVE-2023-50770MEDIUM6.7same product

Jenkins OpenId Connect Authentication Plugin 2.6 and earlier stores a password of a local user account used as...

CVE-2023-24445MEDIUM6.1same product

Jenkins OpenID Plugin 2.4 and earlier improperly determines that a redirect URL after login is legitimately po...

CVE-2019-1003099MEDIUM6.5same product

A missing permission check in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate fo...