A cross-site request forgery vulnerability in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate form validation method allows attackers to initiate a connection to an attacker-specified server.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2022-3230 | A cross-site request forgery vulnerability in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate form validation method allows attackers to initiate a connection to an attacker-specified server. |
![]() |
GHSA-8v26-3p83-mf2g | Jenkins OpenID Plugin CSRF vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-05T03:07:18.292Z
Reserved: 2019-04-03T00:00:00
Link: CVE-2019-1003098

No data.

Status : Modified
Published: 2019-04-04T16:29:02.227
Modified: 2024-11-21T04:17:54.267
Link: CVE-2019-1003098

No data.

No data.