Red Hat Bugzilla – Bug 1565689
CVE-2017-1000244 jenkins-plugin-favorite: CSRF vulnerability in Favorite Plugin allows changing another user’s favorites
Last modified: 2018-06-29 18:36:27 EDT
An API used to add and remove a favorite was vulnerable to CSRF, allowing attackers to change the victim’s favorites. The API now requires requests to be sent via POST, which is subject to the CSRF protection configurable in Jenkins global security configuration. External References: https://jenkins.io/security/advisory/2017-06-06/ Upstream patch: https://github.com/jenkinsci/favorite-plugin/commit/e51869213ba4f197724f4278a771c635a95e5f47