CVE-2019-1003012 Information
Description
A data modification vulnerability exists in Jenkins Blue Ocean Plugins 1.10.1 and earlier in blueocean-core-js/src/js/bundleStartup.js blueocean-core-js/src/js/fetch.ts blueocean-core-js/src/js/i18n/i18n.js blueocean-core-js/src/js/urlconfig.js blueocean-rest/src/main/java/io/jenkins/blueocean/rest/APICrumbExclusion.java blueocean-web/src/main/java/io/jenkins/blueocean/BlueOceanUI.java blueocean-web/src/main/resources/io/jenkins/blueocean/BlueOceanUI/index.jelly that allows attackers to bypass all cross-site request forgery protection in Blue Ocean API.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Reference
https://access.redhat.com/errata/RHBA-2019:0326 https://access.redhat.com/errata/RHBA-2019:0327 https://jenkins.io/security/advisory/2019-01-28/SECURITY-1201 A data modification vulnerability exists in Jenkins Blue Ocean Plugins 1.10.1 and earlier in blueocean-core-js/src/js/bundleStartup.js blueocean-core-js/src/js/fetch.ts blueocean-core-js/src/js/i18n/i18n.js blueocean-core-js/src/js/urlconfig.js blueocean-rest/src/main/java/io/jenkins/blueocean/rest/APICrumbExclusion.java blueocean-web/src/main/java/io/jenkins/blueocean/BlueOceanUI.java blueocean-web/src/main/resources/io/jenkins/blueocean/BlueOceanUI/index.jelly that allows attackers to bypass all cross-site request forgery protection in Blue Ocean API.
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
HIGH
Base Score
NONE
Base Severity
6.5
Share on: