CVE-2018-1000411
published 2019-01-09CVE-2018-1000411: A cross-site request forgery vulnerability exists in Jenkins JUnit Plugin 1.25 and earlier in TestObject.java that allows setting the description of a test…
PriorityP426medium6.5CVSS 3.0
AVNACLPRNUIRSUCNIHAN
EPSS
0.81%
52.6th percentile
A cross-site request forgery vulnerability exists in Jenkins JUnit Plugin 1.25 and earlier in TestObject.java that allows setting the description of a test result.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | arachni_scanner_plugin | — | — |
| jenkins | argus_notifier_plugin | — | — |
| jenkins | artifactory_plugin | — | — |
| jenkins | chatter_notifier_plugin | — | — |
| jenkins | config_file_provider_plugin | — | — |
| jenkins | credentials_plugin | — | — |
| jenkins | crowd_2_integration_plugin | — | — |
| jenkins | dimensions_plugin | — | — |
| jenkins | email_extension_template_plugin | — | — |
| jenkins | git_changelog_plugin | — | — |
| jenkins | hipchat_plugin | — | — |
| jenkins | ids_in_argus_notifier_plugin | — | — |
| jenkins | ids_in_chatter_notifier_plugin | — | — |
| jenkins | ids_in_hipchat_plugin | — | — |
| jenkins | ids_in_mesos_plugin | — | — |
| jenkins | ids_to_allow_administrators_configuring_the_plugin | — | — |
| jenkins | ids_to_allow_users_configuring_the_plugin | — | — |
| jenkins | javamelody_library_bundled_in_monitoring_plugin | — | — |
| jenkins | jira_plugin | — | — |
| jenkins | job_config_history_plugin | — | — |
| jenkins | job_configuration_history_plugin | — | — |
| jenkins | junit | <= 1.25 | — |
| jenkins | junit_plugin | — | — |
| jenkins | mesos_cloud_plugin | — | — |
| jenkins | mesos_plugin | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Jenkins
Jenkins Security Advisory 2018-09-25
vendor_jenkins·2018-09-25·CVSS 6.5
CVE-2017-12197 [MEDIUM] Jenkins Security Advisory 2018-09-25
Title: Jenkins Security Advisory 2018-09-25
Jenkins Security Advisory 2018-09-25
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Arachni Scanner
Plugin
Argus Notifier
Plugin
Artifactory
Plugin
Chatter Notifier
Plugin
Config File Provider
Plugin
crowd2
Plugin
Dimensions
Plugin
Email Extensio
Red Hat
jenkins-plugin-junit: CSRF due to URL not requiring POST requests
vendor_redhat·2018-09-25·CVSS 6.5
CVE-2018-1000411 [MEDIUM] CWE-352 jenkins-plugin-junit: CSRF due to URL not requiring POST requests
jenkins-plugin-junit: CSRF due to URL not requiring POST requests
A cross-site request forgery vulnerability exists in Jenkins JUnit Plugin 1.25 and earlier in TestObject.java that allows setting the description of a test result.
Statement: For Openshift, Jenkins is used within the infrastructure and deployment in OCP. The package is delivered within the technology but not used by default in production environments. It requires additional configuration in running environments which would be mainly use on testing applications being deployed.
The update is in the latest version released with Red Hat OpenShift 3.11.
Package: jenkins-2-plugins (Red Hat OpenShift Container Platform 3.10) - Will not fix
Package: jenkins-2-plugins (Red Hat OpenShift Container Platform 3.11) - Will not fix
Pa
OSV
Jenkins JUnit Plugin CSRF vulnerability
osv·2022-05-14
CVE-2018-1000411 [MEDIUM] Jenkins JUnit Plugin CSRF vulnerability
Jenkins JUnit Plugin CSRF vulnerability
A cross-site request forgery vulnerability exists in Jenkins JUnit Plugin 1.25 and earlier in TestObject.java that allows setting the description of a test result.
GHSA
Jenkins JUnit Plugin CSRF vulnerability
ghsa·2022-05-14
CVE-2018-1000411 [MEDIUM] CWE-352 Jenkins JUnit Plugin CSRF vulnerability
Jenkins JUnit Plugin CSRF vulnerability
A cross-site request forgery vulnerability exists in Jenkins JUnit Plugin 1.25 and earlier in TestObject.java that allows setting the description of a test result.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1000411 jenkins-plugin-junit: CSRF due to URL not requiring POST requests
bugzilla·2018-10-15·CVSS 6.5
CVE-2018-1000411 [MEDIUM] CVE-2018-1000411 jenkins-plugin-junit: CSRF due to URL not requiring POST requests
CVE-2018-1000411 jenkins-plugin-junit: CSRF due to URL not requiring POST requests
A URL used to allow setting the description of a test object in JUnit Plugin did not require POST requests, resulting in a cross-site request forgery vulnerability.
References:
https://jenkins.io/security/advisory/2018-09-25/
Discussion:
External References:
https://jenkins.io/security/advisory/2018-09-25/#SECURITY-1101
https://github.com/jenkinsci/junit-plugin/commit/091ee0dc8dd6023713827ce1a5914fa9fa9b6043
---
Statement:
For Openshift, Jenkins is used within the infrastructure and deployment in OCP. The package is delivered within the technology but not used by default in production environments. It requires additional configuration in running environments which would be mainly use on testing appl
Bugzilla
CVE-2017-1000411 opendaylight: Controller denial-of-service due to "expired" flows taking up the memory resource of CONFIG DS
bugzilla·2017-12-01·CVSS 7.5
CVE-2017-1000411 [HIGH] CVE-2017-1000411 opendaylight: Controller denial-of-service due to "expired" flows taking up the memory resource of CONFIG DS
CVE-2017-1000411 opendaylight: Controller denial-of-service due to "expired" flows taking up the memory resource of CONFIG DS
It was found that multiple "expired" flows can take up the memory resource of CONFIG DS which leads to CONTROLLER shutdown.
Discussion:
Acknowledgments:
Name: Vaibhav Hemant Dixit
---
Statement:
OpenDaylight was released as a technical preview in Red Hat Openstack Platform versions 12 and under. Additionally, upstream have released an advisory outlining recommended actions, they will not be patching against this Denial of Service vector.
---
External References:
https://lists.opendaylight.org/pipermail/opendaylight-announce/2018-January/000027.html
2019-01-09
Published