Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39565
HistoryMar 07, 2023 - 12:49 a.m.

Cross-Site Request Forgery (CSRF)

2023-03-0700:49:05
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
2
cross-site request forgery
jenkins 2
csrf vulnerability
git repository
trigger builds
vulnerable software

8.9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

34.3%

jenkins-2-plugins is vulnerable to Cross-Site Request Forgery (CSRF). An attacker is able to trigger builds of jobs configured to use an attacker-specified Git repository and cause them to check out an attacker-specified commit.

8.9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

34.3%