First published: Wed Nov 01 2017(Updated: )
Jenkins Favorite Plugin version 2.2.0 and older is vulnerable to CSRF resulting in data modification
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Favorite | <=2.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1000244 is classified as medium severity due to its potential for data modification via CSRF attacks.
To fix CVE-2017-1000244, upgrade the Jenkins Favorite Plugin to version 2.2.1 or later.
CVE-2017-1000244 affects Jenkins Favorite Plugin versions up to and including 2.2.0.
Yes, CVE-2017-1000244 can be exploited remotely by an unauthenticated attacker due to the CSRF vulnerability.
CVE-2017-1000244 is a Cross-Site Request Forgery (CSRF) vulnerability that allows modification of data.