Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Takashi Suzuki

#42337de 56,337
6.8CVSS total
Vulnerabilidades · 1
PT-2019-11717
6.8
2019-04-30
Jenkins · Jenkins Gitlab Authentication Plugin · CVE-2019-10315
**Name of the Vulnerable Software and Affected Versions** Jenkins GitHub Authentication Plugin versions 0.31 and earlier **Description** The issue concerns the management of the state parameter of OAuth to prevent CSRF. An attacker could catch the redirect URL provided during the authentication process using OAuth and send it to the victim. If the victim was already connected to Jenkins, their Jenkins account would be attached to the attacker’s GitHub account. **Recommendations** For Jenkins GitHub Authentication Plugin versions 0.31 and earlier, update to a version that correctly manages the state parameter of OAuth to prevent CSRF. As a temporary workaround, consider restricting the use of OAuth authentication until a patch is available.