Jenkins docker-build-step Plugin Cross-Site Request Forgery vulnerability
Moderate severity
GitHub Reviewed
Published
Mar 6, 2024
to the GitHub Advisory Database
•
Updated Oct 28, 2024
Package
Affected versions
<= 2.11
Patched versions
None
Description
Published by the National Vulnerability Database
Mar 6, 2024
Published to the GitHub Advisory Database
Mar 6, 2024
Reviewed
Mar 6, 2024
Last updated
Oct 28, 2024
A cross-site request forgery (CSRF) vulnerability in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test parameters, affecting future build step executions.
References