Lucene search

K
osvGoogleOSV:GHSA-HGPQ-42PF-9VFQ
HistoryMay 18, 2022 - 12:00 a.m.

Cross Site Request Forgery in Jenkins Blue Ocean Plugin

2022-05-1800:00:40
Google
osv.dev
10

0.001 Low

EPSS

Percentile

35.1%

A cross-site request forgery (CSRF) vulnerability in Jenkins Blue Ocean Plugin 1.25.3 and earlier allows attackers to connect to an attacker-specified HTTP server. Blue Ocean Plugin 1.25.4 requires POST requests and the appropriate permissions for the affected HTTP endpoints.

0.001 Low

EPSS

Percentile

35.1%