CVE-2019-10307

MEDIUM4.3EPSS 0.18%

Jenkins Static Analysis Utilities Plugin is vulnerable to Cross-site request forgery vulnerability

Published: 5/24/2022Modified: 2/16/2024

Description

Jenkins analysis-core Plugin has the capability to allow other plugins to display trend graphs for their static analysis results. analysis-core Plugin provides the configuration form for the default settings of each graph. The configuration form and form submission handler did not perform a permission check, allowing attackers with Job/Read access to change the per-job graph configuration defaults for all users. Additionally, the form submission handler did not require POST requests, resulting in a cross-site request forgery vulnerability. analysis-core Plugin now requires Job/Configure permission and POST requests to configure the per-job graph defaults for all users.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.3CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

References (5)