Lucene search

K
osvGoogleOSV:GHSA-R8RW-XX57-M64Q
HistoryMay 14, 2022 - 1:06 a.m.

Cross-Site Request Forgery in Jenkins Git Plugin

2022-05-1401:06:45
Google
osv.dev
15
jenkins
git plugin
cross-site request forgery
vulnerability
workspace
metadata
build record

EPSS

0.002

Percentile

53.6%

A cross-site request forgery vulnerability exists in Jenkins Git Plugin 3.9.1 and earlier in src/main/java/hudson/plugins/git/GitTagAction.java that allows attackers to create a Git tag in a workspace and attach corresponding metadata to a build record.