Lucene search

K
osvGoogleOSV:GHSA-9F37-GGXM-H6WX
HistoryMay 24, 2022 - 5:35 p.m.

CSRF vulnerability in Jenkins Shelve Project Plugin

2022-05-2417:35:08
Google
osv.dev
9

0.001 Low

EPSS

Percentile

25.1%

Jenkins Shelve Project Plugin 3.0 and earlier does not require POST requests for HTTP endpoints, resulting in cross-site request forgery (CSRF) vulnerabilities.

These vulnerabilities allow attackers to shelve, unshelve, or delete a project.

Jenkins Shelve Project Plugin 3.1 requires POST requests for the affected HTTP endpoints.

0.001 Low

EPSS

Percentile

25.1%

Related for OSV:GHSA-9F37-GGXM-H6WX