Jenkins Slack Notification Plugin CSRF vulnerability and missing permission checks
High severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Jan 9, 2024
Description
Published by the National Vulnerability Database
Mar 28, 2019
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jan 9, 2024
Last updated
Jan 9, 2024
A cross-site request forgery vulnerability in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
References