漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
A data modification vulnerability exists in Jenkins Blue Ocean Plugins 1.10.1 and earlier in blueocean-core-js/src/js/bundleStartup.js, blueocean-core-js/src/js/fetch.ts, blueocean-core-js/src/js/i18n/i18n.js, blueocean-core-js/src/js/urlconfig.js, blueocean-rest/src/main/java/io/jenkins/blueocean/rest/APICrumbExclusion.java, blueocean-web/src/main/java/io/jenkins/blueocean/BlueOceanUI.java, blueocean-web/src/main/resources/io/jenkins/blueocean/BlueOceanUI/index.jelly that allows attackers to bypass all cross-site request forgery protection in Blue Ocean API.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
CloudBees Jenkins Blue Ocean Plugins 跨站请求伪造漏洞
Vulnerability Description
Jenkins Blue Ocean Plugins 1.10.1及之前版本中存在跨站请求伪造漏洞。远程攻击者可利用该漏洞执行未授权的操作。(多个文件包括:blueocean-core-js/src/js/bundleStartup.js、 blueocean-core-js/src/js/fetch.ts、 blueocean-core-js/src/js/i18n/i18n.js、 blueocean-core-js/src/js/urlconfig.js、 blueocean-rest/src/ma
CVSS Information
N/A
Vulnerability Type
N/A