{"id":"GHSA-99hj-ppg3-2xwc","summary":"Cross-Site Request Forgery in Jenkins","details":"A race condition during Jenkins 2.94 and earlier; 2.89.1 and earlier startup could result in the wrong order of execution of commands during initialization. There is a very short window of time after startup during which Jenkins may no longer show the 'Please wait while Jenkins is getting ready to work' message but Cross-Site Request Forgery (CSRF) protection may not yet be effective.","aliases":["CVE-2017-1000504"],"modified":"2024-03-04T21:31:04.038610Z","published":"2022-05-14T01:04:36Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-07-01T21:45:12Z","nvd_published_at":"2018-01-24T23:29:00Z","cwe_ids":["CWE-352"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-1000504"},{"type":"WEB","url":"https://github.com/jenkinsci/jenkins/commit/ccc374a7176d7704941fb494589790b7673efe2"},{"type":"PACKAGE","url":"https://github.com/jenkinsci/jenkins"},{"type":"WEB","url":"https://jenkins.io/security/advisory/2017-12-14"}],"affected":[{"package":{"name":"org.jenkins-ci.main:jenkins-core","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.main/jenkins-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.81"},{"fixed":"2.89.2"}]}],"versions":["2.81","2.82","2.83","2.84","2.85","2.86","2.87","2.88","2.89","2.89.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-99hj-ppg3-2xwc/GHSA-99hj-ppg3-2xwc.json","last_known_affected_version_range":"\u003c= 2.89.1"}},{"package":{"name":"org.jenkins-ci.main:jenkins-core","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.main/jenkins-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.90"},{"fixed":"2.95"}]}],"versions":["2.90","2.91","2.92","2.93","2.94"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-99hj-ppg3-2xwc/GHSA-99hj-ppg3-2xwc.json","last_known_affected_version_range":"\u003c= 2.94"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}