Описание
Cross-Site Request Forgery in Jenkins Build Failure Analyzer Plugin
A cross-site request forgery vulnerability in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier allows attackers to have Jenkins evaluate a computationally expensive regular expression.
Пакеты
Наименование
com.sonyericsson.jenkins.plugins.bfa:build-failure-analyzer
maven
Затронутые версииВерсия исправления
< 1.24.2
1.24.2
Связанные уязвимости
CVSS3: 8.8
nvd
около 6 лет назад
A cross-site request forgery vulnerability in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier allows attackers to have Jenkins evaluate a computationally expensive regular expression.