Lucene search

K
osvGoogleOSV:GHSA-63MW-HP3H-GC77
HistoryMay 24, 2022 - 5:17 p.m.

CSRF vulnerability in Jenkins CVS Plugin

2022-05-2417:17:14
Google
osv.dev
4

0.001 Low

EPSS

Percentile

26.7%

CVS Plugin 2.15 and earlier does not require POST requests in several HTTP endpoints, resulting in cross-site request forgery (CSRF) vulnerabilities. This allows attackers to create and manipulate tags, and to connect to an attacker-specified URL.

CVS Plugin 2.16 now requires POST requests for the affected HTTP endpoints.

0.001 Low

EPSS

Percentile

26.7%

Related for OSV:GHSA-63MW-HP3H-GC77