Cross-site request forgery In org.jenkins-ci.plugins:docker-build-step
Description
Jenkins docker-build-step Plugin Cross-Site Request Forgery vulnerability A cross-site request forgery (CSRF) vulnerability in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test parameters, affecting future build step executions.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version |
|---|---|---|
maven |
Aliases
1. 2. 3. 4.
References
1. 2.