GHSA-j2h6-j34w-g5vp, CVE-2018-1000013
maven/org.jenkins-ci.plugins/release
Cross-Site Request Forgery (CSRF)
Jenkins Release Plugin 2.9 and earlier does not require form submissions to be submitted via POST, resulting in a CSRF vulnerability allowing attackers to trigger release builds.
All versions before 2.10
Upgrade to version 2.10 or above.
2024-01-31
source |