Cross-Site Request Forgery (CSRF) vulnerability in Jenkins global-build-stats plugin
Moderate severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Jan 30, 2024
Package
Affected versions
<= 1.4
Patched versions
1.5
Description
Published by the National Vulnerability Database
Jan 26, 2018
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
Jan 30, 2024
Last updated
Jan 30, 2024
Some URLs provided by Jenkins global-build-stats plugin version 1.4 and earlier returned a JSON response that contained request parameters. These responses had the Content Type: text/html, so could have been interpreted as HTML by clients, resulting in a potential reflected cross-site scripting vulnerability. Additionally, some URLs provided by global-build-stats plugin that modify data did not require POST requests to be sent, resulting in a potential cross-site request forgery vulnerability.
References