A cross-site request forgery vulnerability exists in Jenkins Git Plugin 3.9.1 and earlier in src/main/java/hudson/plugins/git/GitTagAction.java that allows attackers to create a Git tag in a workspace and attach corresponding metadata to a build record.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat Openshift | — | Upgrade golang-github-prometheus-node_exporterUpgrade atomic-openshift-node-problem-detectorUpgrade openshift-enterprise-cluster-capacityUpgrade atomic-enterprise-service-catalogUpgrade jenkinsUpgrade golang-github-prometheus-prometheusUpgrade openshift-enterprise-autohealUpgrade atomic-openshift-cluster-autoscalerUpgrade atomic-openshift-dockerregistryUpgrade haproxyUpgrade atomic-openshift-deschedulerUpgrade atomic-openshift-web-consoleUpgrade atomic-openshift-metrics-serverUpgrade openshift-ansibleUpgrade atomic-openshift-service-idlerUpgrade jenkins-2-pluginsUpgrade golang-github-prometheus-alertmanagerUpgrade atomic-openshiftUpgrade golang-github-openshift-oauth-proxy | Mar 15, 2019 | Jan 28, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub