CVE-2018-1000414

HIGH8.1EPSS 0.07%

CSRF vulnerability in Config File Provider Plugin

Published: 5/14/2022Modified: 2/16/2024

Description

A cross-site request forgery vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in ConfigFilesManagement.java, FolderConfigFileAction.java that allows creating and editing configuration file definitions.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.1CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

References (4)