Bug 1670298 (CVE-2019-1003012) - CVE-2019-1003012 jenkins-plugin-blueocean: Blue Ocean did not require CSRF tokens (SECURITY-1201)
Summary: CVE-2019-1003012 jenkins-plugin-blueocean: Blue Ocean did not require CSRF to...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2019-1003012
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1671469 1671470
Blocks: 1670285
TreeView+ depends on / blocked
 
Reported: 2019-01-29 07:54 UTC by Sam Fowler
Modified: 2021-10-27 03:24 UTC (History)
18 users (show)

Fixed In Version: jenkins-plugin-blueocean 1.10.2
Clone Of:
Environment:
Last Closed: 2021-10-27 03:24:28 UTC
Embargoed:


Attachments (Terms of Use)

Description Sam Fowler 2019-01-29 07:54:49 UTC
Jenkins Blue Ocean plugin before version 1.10.2 did not require CSRF tokens ("crumbs") for POST requests with the Content-Type: application/json.

Blue Ocean now requires that valid CSRF tokens are present in POST requests.


External Reference:

https://jenkins.io/security/advisory/2019-01-28/#SECURITY-1201

Upstream patches:

https://github.com/jenkinsci/blueocean-plugin/commit/1a03020b5a50c1e3f47d4b0902ec7fc78d3c86ce

Comment 1 Paul Harvey 2019-02-04 06:29:18 UTC
openshift-enterprise 3.4-3.11 inclusive: affected

Once openshift3/jenkins-1-rhel7, openshift3/jenkins-2-rhel7, openshift3/jenkins-slave-base-rhel7 container images have been released with these fixes, users of all versions of openshift-enterprise-3.2+ are encouraged to update these container images in their environment.


Note You need to log in before you can comment on or make changes to this bug.