Jenkins Release Plugin CVE-2018-1000013 Cross Site Request Forgery Vulnerability
BID:102834
CVE-2018-1000013 |Info
Jenkins Release Plugin CVE-2018-1000013 Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 102834 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-1000013 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 22 2018 12:00AM |
| Updated: | Jan 22 2018 12:00AM |
| Credit: | Jesse Glick, CloudBees, Inc. |
| Vulnerable: |
Jenkins-Ci Release Plugin 2.9 |
| Not Vulnerable: |
Jenkins-Ci Release Plugin 2.10 |
Discussion
Jenkins Release Plugin CVE-2018-1000013 Cross Site Request Forgery Vulnerability
Release Plugin for Jenkins is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.
Release Plugin version 2.9 and prior versions are vulnerable.
Release Plugin for Jenkins is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.
Release Plugin version 2.9 and prior versions are vulnerable.
Exploit / POC
Jenkins Release Plugin CVE-2018-1000013 Cross Site Request Forgery Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim to follow a malicious URI.
To exploit this issue, an attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
Jenkins Release Plugin CVE-2018-1000013 Cross Site Request Forgery Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Jenkins Release Plugin CVE-2018-1000013 Cross Site Request Forgery Vulnerability
References:
References:
- Jenkins CI Homepage (Jenkins CI)
- Jenkins Security Advisory 2018-01-22 (Jenkins CI)