A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and earlier, LTS 2.319.1 and earlier allows attackers to trigger build of job without parameters when no security realm is set.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://www.jenkins.io/security/advisory/2022-01-12/#SECURITY-2558 | vendor advisory |
http://www.openwall.com/lists/oss-security/2022/01/12/6 | third party advisory mailing list |
https://www.oracle.com/security-alerts/cpuapr2022.html | third party advisory patch |