scm-manager is vulnerable to Cross-Site Request Forgery (CSRF)
42
Medium Risk
HTTP endpoints that connect to attacker-specified URLs with attacker-specified credentials IDs do not require POST requests. An attacker can forge requests from a victim's browser to capture credentials stored in Jenkins. The fix requires POST requests for those endpoints.
You are affected if you are using a version that falls within the vulnerable range and authenticated users can be induced to visit attacker-controlled pages while logged into Jenkins.
scm-manager is vulnerable to Cross-Site Request Forgery (CSRF) in versions 0.0.1 - 1.11.1.
Upgrade the io.jenkins.plugins:scm-manager library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant