A cross-site request forgery (CSRF) vulnerability in Jenkins Config File Provider Plugin 3.7.0 and earlier allows attackers to delete configuration files corresponding to an attacker-specified ID.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat Openshift | — | Upgrade openshift-kuryrUpgrade openvswitch2.15Upgrade rust-afterburnUpgrade python-oslo-i18nUpgrade python-ironic-prometheus-exporterUpgrade rteval-loadsUpgrade python-oslo-serviceUpgrade python-toozUpgrade redhat-release-coreosUpgrade python-oslo-upgradecheckUpgrade ovn2.13Upgrade python-oslo-serializationUpgrade atomic-openshift-service-idlerUpgrade python-oslo-logUpgrade openstack-ironic-python-agentUpgrade python-oslo-concurrencyUpgrade python-sushy-oem-idracUpgrade jenkins-2-pluginsUpgrade butaneUpgrade python-hardwareUpgrade runcUpgrade python-ironic-libUpgrade console-login-helper-messagesUpgrade ostreeUpgrade python-eventletUpgrade kata-containersUpgrade python-openshiftUpgrade coreos-installerUpgrade python-stevedoreUpgrade python-debtcollectorUpgrade toolboxUpgrade python-pyrsistentUpgrade ignitionUpgrade cri-oUpgrade ironic-images-ipa-ppc64leUpgrade haproxyUpgrade python-openstacksdkUpgrade cri-toolsUpgrade ironic-imagesUpgrade openstack-ironicUpgrade python-oslo-utilsUpgrade openshiftUpgrade ironic-images-ipa-x86_64Upgrade podmanUpgrade python-oslo-configUpgrade python-sushyUpgrade openshift-clientsUpgrade python-oslo-policyUpgrade openshift-ansibleUpgrade python-kubernetesUpgrade jenkinsUpgrade python-oslo-contextUpgrade python-keystoneauth1Upgrade python-jsonschemaUpgrade openstack-ironic-inspectorUpgrade python-oslo-db | Jun 2, 2021 | Apr 21, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub