A cross-site request forgery (CSRF) vulnerability in Jenkins External Monitor Job Type Plugin 191.v363d0d1efdf8 and earlier allows attackers to create runs of an external job.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2762 | vendor advisory |
http://www.openwall.com/lists/oss-security/2022/07/27/1 | third party advisory mailing list |