Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40619
HistoryMay 21, 2023 - 9:59 a.m.

Cross-site Request Forgery (CSRF)

2023-05-2109:59:34
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
cross-site request forgery
csrf
jenkins
http endpoint
vulnerability

0.0005 Low

EPSS

Percentile

16.2%

org.jenkins-ci.plugins:email-ext is vulnerable to Cross-Site Request Forgery (CSRF). An attacker is able to make another user stop watching an attacker-specified job because the library does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery.

0.0005 Low

EPSS

Percentile

16.2%