QID 997480
Date Published: 2024-02-26
QID 997480: Java (Maven) Security Update for org.jenkins-ci.plugins:role-strategy (GHSA-774g-r3fm-4v85)
Role-based Authorization Strategy Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks. This allowed attackers to add administrator role to any user, or to remove the authorization configuration, preventing legitimate access to Jenkins.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-774g-r3fm-4v85 for updates and patch information.
Vendor References
- GHSA-774g-r3fm-4v85 -
github.com/advisories/GHSA-774g-r3fm-4v85
CVEs related to QID 997480
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-774g-r3fm-4v85 | org.jenkins-ci.plugins:role-strategy |
|