CVE-2021-21620

MEDIUM4.3EPSS 0.25%

Cross-Site Request Forgery in the Jenkins Claim plugin

Published: 6/16/2021Modified: 2/16/2024
Also known as:GHSA-4ffq-6g62-j4v4

Description

Jenkins Claim Plugin 2.18.1 and earlier does not require POST requests for the form submission endpoint assigning claims, resulting in a cross-site request forgery (CSRF) vulnerability. This vulnerability allows attackers to change claims. Jenkins Claim Plugin 2.18.2 requires POST requests for the affected HTTP endpoint.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.3CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

References (3)