CVE-2021-21627

HIGH8.8EPSS 0.07%

CSRF vulnerability in Jenkins Libvirt Agents Plugin

發布日:2022/5/24修改日:2024/2/16

描述

Jenkins Libvirt Agents Plugin 1.9.0 and earlier does not require POST requests for a form submission endpoint, resulting in a cross-site request forgery (CSRF) vulnerability. This vulnerability allows attackers to stop hypervisor domains. Jenkins Libvirt Agents Plugin 1.9.1 requires POST requests for the affected HTTP endpoint.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH8.8CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

參考連結(5)