{"id":"GHSA-774g-r3fm-4v85","summary":"CSRF vulnerability in Jenkins Role-based Authorization Strategy Plugin configuration","details":"Role-based Authorization Strategy Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks. This allowed attackers to add administrator role to any user, or to remove the authorization configuration, preventing legitimate access to Jenkins.","aliases":["CVE-2017-1000090"],"modified":"2024-02-18T05:32:42.483351Z","published":"2022-05-17T00:29:02Z","database_specific":{"cwe_ids":["CWE-352"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-01-30T22:39:23Z","nvd_published_at":"2017-10-05T01:29:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-1000090"},{"type":"WEB","url":"https://jenkins.io/security/advisory/2017-07-10"}],"affected":[{"package":{"name":"org.jenkins-ci.plugins:role-strategy","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins/role-strategy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.5.1"}]}],"versions":["1.1.2","1.1.3","2.1.0","2.2.0","2.3.0","2.3.1","2.3.2","2.4.0","2.5.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-774g-r3fm-4v85/GHSA-774g-r3fm-4v85.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}