CVE-2017-1000092

HIGH

Jenkins Git Plugin - Cross-Site Request Forgery via Form Validation

Title source: llm
STIX 2.1

Description

Git Plugin connects to a user-specified Git repository as part of form validation. An attacker with no direct access to Jenkins but able to guess at a username/password credentials ID could trick a developer with job configuration permissions into following a link with a maliciously crafted Jenkins URL which would result in the Jenkins Git client sending the username and password to an attacker-controlled server.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/100435
Vendor Advisory x_refsource_confirm
https://jenkins.io/security/advisory/2017-07-10/

Scores

CVSS v3 7.5
EPSS 0.0015
EPSS Percentile 34.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (50)
jenkins/git 0.1.0
jenkins/git 0.2.0
jenkins/git 0.3.0
jenkins/git 0.4.0
jenkins/git 0.5.0
jenkins/git 0.6.0
jenkins/git 0.7.0
jenkins/git 0.7.1
jenkins/git 0.7.2
jenkins/git 0.7.3
... and 40 more
Published Oct 05, 2017
Tracked Since Feb 18, 2026