Lucene search

K
osvGoogleOSV:GHSA-MQJ3-FC39-73FJ
HistoryMay 24, 2022 - 10:00 p.m.

Cross-site request forgery vulnerability in Jenkins Artifactory Plugin

2022-05-2422:00:03
Google
osv.dev
5
jenkins
artifactory plugin
vulnerability
cross-site request forgery
releaseaction
gradlereleaseapiaction
mavenreleaseapiaction
unifiedpromotebuildaction

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

50.5%

A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ReleaseAction#doSubmit, GradleReleaseApiAction#doStaging, MavenReleaseApiAction#doStaging, and UnifiedPromoteBuildAction#doSubmit allowed attackers to schedule a release build, perform release staging for Gradle and Maven projects, and promote previously staged builds, respectively.

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

50.5%

Related for OSV:GHSA-MQJ3-FC39-73FJ