CVE-2019-1003098: CSRF
A cross-site request forgery vulnerability in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate form validation method allows attackers to initiate a connection to an attacker-specified server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1003098?
CVE-2019-1003098 has a medium severity rating due to its potential to allow cross-site request forgery attacks.
How do I fix CVE-2019-1003098?
To fix CVE-2019-1003098, update the Jenkins openid Plugin to a version that addresses this vulnerability.
What impact does CVE-2019-1003098 have on my Jenkins installation?
CVE-2019-1003098 allows attackers to initiate connections to arbitrary servers, which may compromise your Jenkins installation's security.
Which versions of Jenkins are affected by CVE-2019-1003098?
CVE-2019-1003098 affects all versions of the Jenkins openid Plugin prior to the fix being implemented.
Is there a proof of concept available for CVE-2019-1003098?
Yes, proof-of-concept exploits for CVE-2019-1003098 have been discussed in various security forums.