Lucene search

K
osvGoogleOSV:GHSA-X24M-WR2F-P3VC
HistoryMay 24, 2022 - 5:01 p.m.

Jenkins Google Compute Engine Plugin Cross-Site Request Forgery vulnerability

2022-05-2417:01:41
Google
osv.dev
9

0.001 Low

EPSS

Percentile

33.0%

A cross-site request forgery vulnerability in Jenkins Google Compute Engine Plugin 4.1.1 and earlier in ComputeEngineCloud#doProvision could be used to provision new agents. Google Compute Engine Plugin 4.2.0 requires POST requests for this API endpoint.

0.001 Low

EPSS

Percentile

33.0%

Related for OSV:GHSA-X24M-WR2F-P3VC