CloudBees Jenkins CSRF mechanism Bypass Vulnerability (CVE-2015-5318)
CloudBees Jenkins CSRF mechanism Bypass Vulnerability (CVE-2015-5318)
Release date:
Updated on:
Affected Systems:
CloudBees Jenkins <LTS 1.625.2
CloudBees Jenkins <1.638
Description:
CVE (CAN) ID: CVE-2015-5318
CloudBees Jenkins is an open-source continuous Integration Server.
In versions earlier than CloudBees Jenkins 1.638 and LTS 1.625.2, CSRF protection tokens are generated using the public salt. Remote attackers can bypass the CSRF protection mechanism through brute force attacks.
<* Source: Jenkins
James Nord
*>
Suggestion:
Vendor patch:
CloudBees
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11-11
Https://jenkins-ci.org/content/mitigating-unauthenticated-remote-code-execution-0-day-jenkins-cli
This article permanently updates the link address: