PT-2019-11755 · Jenkins · Jenkins Maven Release Plugin+1
Oleg Nenashev
·
Published
2019-07-31
·
Updated
2023-10-25
·
CVE-2019-10359
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Jenkins Maven Release Plugin versions 0.14.0 and earlier
Jenkins Maven Release Plugin versions prior to 0.15.0
Description
A cross-site request forgery issue allows attackers to perform releases with attacker-specified options in the
M2ReleaseAction#doSubmit method.Recommendations
For Jenkins Maven Release Plugin versions 0.14.0 and earlier, update to version 0.15.0 or later.
For Jenkins Maven Release Plugin versions prior to 0.15.0, update to version 0.15.0 or later.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Maven Release Plugin