CVE-2018-1000414 - CERT CVE
ID CVE-2018-1000414
Sažetak A cross-site request forgery vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in ConfigFilesManagement.java, FolderConfigFileAction.java that allows creating and editing configuration file definitions.
Reference
CVSS
Base: 5.8
Impact: 4.9
Exploitability:8.6
Pristup
VektorSloženostAutentikacija
NETWORK MEDIUM NONE
Impact
PovjerljivostCjelovitostDostupnost
NONE PARTIAL PARTIAL
CVSS vektor AV:N/AC:M/Au:N/C:N/I:P/A:P
Zadnje važnije ažuriranje 22-01-2019 - 14:35
Objavljeno 09-01-2019 - 23:29