Jenkins Translation Assistance Plugin 1.15 and earlier did not require form submissions to be submitted via POST, resulting in a CSRF vulnerability allowing attackers to override localized strings displayed to all users on the current Jenkins instance if the victim is a Jenkins administrator.
원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-1000014
원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-1000014
댓글 0
번호 | 제목 | 글쓴이 | 날짜 | 조회 수 |
---|---|---|---|---|
452 | CVE-2017-11398 | 관리자 | 2018.01.25 | 33 |
451 | CVE-2017-12098 | 관리자 | 2018.01.25 | 15 |
450 | CVE-2017-15713 | 관리자 | 2018.01.25 | 9 |
449 | CVE-2017-18044 | 관리자 | 2018.01.25 | 15 |
448 | CVE-2017-7325 | 관리자 | 2018.01.25 | 10 |
447 | CVE-2017-7326 | 관리자 | 2018.01.25 | 10 |
446 | CVE-2017-7327 | 관리자 | 2018.01.25 | 9 |
445 | CVE-2014-4919 | 관리자 | 2018.01.25 | 6 |
444 | CVE-2015-6926 | 관리자 | 2018.01.25 | 8 |
443 | CVE-2017-6142 | 관리자 | 2018.01.25 | 9 |
442 | CVE-2018-1362 | 관리자 | 2018.01.25 | 14 |
441 | CVE-2017-1693 | 관리자 | 2018.01.25 | 12 |
440 | CVE-2018-5786 | 관리자 | 2018.01.25 | 12 |
439 | CVE-2018-5785 | 관리자 | 2018.01.25 | 9 |
438 | CVE-2018-5784 | 관리자 | 2018.01.25 | 13 |