jenkins-core is vulnerable to Cross-Site Request Forgery (CSRF)
88
High Risk
An HTTP endpoint that serves dynamically generated JavaScript embeds the user's CSRF crumb as a string literal. An attacker who controls a page on the same site as Jenkins can read that crumb from the targeted user's session and perform actions on their behalf. The fix stops embedding the crumb as a string literal in those generated scripts.
You are affected if you are using a version that falls within the vulnerable range and an attacker can host content on the same site as Jenkins that a logged-in user may visit.
jenkins-core is vulnerable to Cross-Site Request Forgery (CSRF) in versions 2.447 - 2.568.2 and 2.569 - 2.579.
Upgrade the org.jenkins-ci.main:jenkins-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.