CVE-2018-1000013

Cross-Site Request Forgery (CSRF) in maven/org.jenkins-ci.plugins/release

Identifiers

GHSA-j2h6-j34w-g5vp, CVE-2018-1000013

Package Slug

maven/org.jenkins-ci.plugins/release

Vulnerability

Cross-Site Request Forgery (CSRF)

Description

Jenkins Release Plugin 2.9 and earlier does not require form submissions to be submitted via POST, resulting in a CSRF vulnerability allowing attackers to trigger release builds.

Affected Versions

All versions before 2.10

Solution

Upgrade to version 2.10 or above.

Last Modified

2024-01-31

source