CloudBees Assurance Plugin 2.276.0.3

1 minute read

RELEASED: Public: 2021-06-02

Security advisory

CloudBees Assurance Plugin 2.276.0.3 requires POST requests for the reconfigure HTTP endpoint.

Security fixes

CloudBees Assurance Plugin 2.276.0.2 and earlier does not require POST requests for the form submission endpoint reconfiguring the update center, resulting in a cross-site request forgery (CSRF) vulnerability.

This vulnerability allows attackers to configure the default update center removing the one already applied.

Fix Description: CloudBees Assurance Plugin 2.276.0.3 requires POST requests for the reconfigure HTTP endpoint.