#VU47189 Cross-site request forgery in Lockable Resources - CVE-2020-2281

 

#VU47189 Cross-site request forgery in Lockable Resources - CVE-2020-2281

Published: September 23, 2020 / Updated: September 30, 2020


Vulnerability identifier: #VU47189
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-2281
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Lockable Resources
Software vendor:
Jenkins

Description

The vulnerability allows a remote attacker to perform cross-site request forgery attacks.

The vulnerability exists due to insufficient validation of the HTTP request origin. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website, such as reserve, unreserve, unlock and reset resources.


Remediation

Install update from vendor's website.

External links