CVE-2013-0329: CSRF
Jenkins Security Advisory 2013-02-16
Another vulnerability allowed an attacker to bypass the CSRF protection mechanism in place, thereby mounting more CSRF attackes.
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-02-16
Other sources
Unspecified vulnerability in Jenkins before 1.502 and LTS before 1.480.3 allows remote attackers to bypass the CSRF protection mechanism via unknown attack vectors.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0329?
CVE-2013-0329 has a medium severity rating due to its ability to bypass CSRF protection mechanisms.
How do I fix CVE-2013-0329?
To fix CVE-2013-0329, update Jenkins to version 1.480.3 or later for the affected versions.
Which versions of Jenkins are affected by CVE-2013-0329?
CVE-2013-0329 affects Jenkins versions up to and including 1.480.2 and 1.501.
What type of attack does CVE-2013-0329 enable?
CVE-2013-0329 enables attackers to perform Cross-Site Request Forgery (CSRF) attacks.
Is there a workaround for CVE-2013-0329 if I cannot update Jenkins?
There are no known workarounds for CVE-2013-0329, so it is recommended to apply the update as soon as possible.