Favorite Plugin for Jenkins is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.
Favorite Plugin 2.2.0 and 2.1.0 are vulnerable.
Information
Jenkins-Ci Favorite Plugin 2.1
Exploit
To exploit this issue, an attacker must entice an unsuspecting victim to follow a malicious URI.
References:
- Jenkins CI Homepage (Jenkins CI)
- jenkins home page (jenkins)
- Jenkins Security Advisory 2017-06-06 (jenkins)