Description
Jenkins GitHub Authentication Plugin 0.31 and earlier did not use the state parameter of OAuth to prevent CSRF.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/04/30/5
http://www.securityfocus.com/bid/108159
https://jenkins.io/security/advisory/2019-04-30/#SECURITY-443
Related Vulnerabilities
CVE-2020-13921 Vulnerability in maven package org.apache.skywalking:storage-jdbc-hikaricp-plugin
CVE-2016-6497 Vulnerability in maven package org.xbib.groovy:groovy-ldap
CVE-2021-21343 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2021-41571 Vulnerability in maven package org.apache.pulsar:pulsar
CVE-2021-46062 Vulnerability in maven package net.mingsoft:ms-mcms