Lucene search

K
osvGoogleOSV:GHSA-W24G-24QG-V4W2
HistoryMay 24, 2022 - 5:45 p.m.

CSRF vulnerability in Jenkins Build With Parameters Plugin

2022-05-2417:45:44
Google
osv.dev
7

0.001 Low

EPSS

Percentile

33.3%

Jenkins Build With Parameters Plugin 1.5 and earlier does not require POST requests for its form submission endpoint, resulting in a cross-site request forgery (CSRF) vulnerability.

This vulnerability allows attackers to build a project with attacker-specified parameters. Build With Parameters Plugin 1.5.1 requires POST requests for the affected HTTP endpoint.

0.001 Low

EPSS

Percentile

33.3%

Related for OSV:GHSA-W24G-24QG-V4W2