PT-2019-11755 · Jenkins · Jenkins Maven Release Plugin+1

Oleg Nenashev

·

Published

2019-07-31

·

Updated

2023-10-25

·

CVE-2019-10359

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Jenkins Maven Release Plugin versions 0.14.0 and earlier Jenkins Maven Release Plugin versions prior to 0.15.0
Description A cross-site request forgery issue allows attackers to perform releases with attacker-specified options in the M2ReleaseAction#doSubmit method.
Recommendations For Jenkins Maven Release Plugin versions 0.14.0 and earlier, update to version 0.15.0 or later. For Jenkins Maven Release Plugin versions prior to 0.15.0, update to version 0.15.0 or later.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2019-10359
GHSA-R4RV-CQ77-6P24

Affected Products

Jenkins
Jenkins Maven Release Plugin