Jenkins Sonar Gerrit Plugin vulnerable to Cross-Site Request Forgery
Moderate severity
GitHub Reviewed
Published
Dec 12, 2022
to the GitHub Advisory Database
•
Updated Jan 5, 2024
Package
Affected versions
<= 377.v8f3808963dc5
Patched versions
378.vf4646d4df087
Description
Published by the National Vulnerability Database
Dec 12, 2022
Published to the GitHub Advisory Database
Dec 12, 2022
Reviewed
Dec 12, 2022
Last updated
Jan 5, 2024
A cross-site request forgery (CSRF) vulnerability in Jenkins Sonar Gerrit Plugin 377.v8f3808963dc5 and earlier allows attackers to have Jenkins connect to Gerrit servers (previously configured by Jenkins administrators) using attacker-specified credentials IDs obtained through another method, potentially capturing credentials stored in Jenkins.
References