Files
CVEs-PoC/2019/CVE-2019-10310.md
T
2024-05-26 14:27:05 +02:00

891 B

CVE-2019-10310

Description

A cross-site request forgery vulnerability in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doTestTowerConnection form validation method allowed attackers permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins

POC

Reference

No PoCs from references.

Github