CVE-2019-10359

Cross-Site Request Forgery (CSRF) in maven/org.jenkins-ci.plugins.m2release/m2release

Identifiers

GHSA-r4rv-cq77-6p24, CVE-2019-10359

Package Slug

maven/org.jenkins-ci.plugins.m2release/m2release

Vulnerability

Cross-Site Request Forgery (CSRF)

Description

A cross-site request forgery vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier in the M2ReleaseAction#doSubmit method allowed attackers to perform releases with attacker-specified options.

Affected Versions

All versions before 0.15.0

Solution

Upgrade to version 0.15.0 or above.

Last Modified

2023-02-03

source