CVE-2019-10315
Jenkins GitHub Authentication Plugin Cross-Site Request Forgery vulnerability
4.3
MEDIUM
CVSS 3.1
EPSS 2.1%
描述
Jenkins GitHub Authentication Plugin did not manage the state parameter of OAuth to prevent CSRF. This allowed an attacker to catch the redirect URL provided during the authentication process using OAuth and send it to the victim. If the victim was already connected to Jenkins, their Jenkins account would be attached to the attacker’s GitHub account. The state parameter is now correctly managed.
如何修補 CVE-2019-10315
要修補 CVE-2019-10315,請將受影響套件升級到下列已修補版本。
- —升級至 0.32 或更新版本
CVE-2019-10315 正在被利用嗎?
低 — EPSS 為 2.1%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 0.32
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L |