CVE-2019-1003012: Cross-Site Request Forgery (CSRF)
(updated )
A data modification vulnerability exists in Jenkins Blue Ocean Plugins in blueocean-core-js/src/js/bundleStartup.js
, blueocean-core-js/src/js/fetch.ts
, blueocean-core-js/src/js/i18n/i18n.js
, blueocean-core-js/src/js/urlconfig.js
, blueocean-rest/src/main/java/io/jenkins/blueocean/rest/APICrumbExclusion.java
, blueocean-web/src/main/java/io/jenkins/blueocean/BlueOceanUI.java
, blueocean-web/src/main/resources/io/jenkins/blueocean/BlueOceanUI/index.jelly
that allows attackers to bypass all cross-site request forgery protection in Blue Ocean API.
References
Detect and mitigate CVE-2019-1003012 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →