Описание
Cross-Site Request Forgery in Jenkins Failed Job Deactivator Plugin
A cross-site request forgery (CSRF) vulnerability in Jenkins Failed Job Deactivator Plugin 1.2.1 and earlier allows attackers to disable jobs. This CSRF vulnerability is only exploitable in Jenkins 2.286 and earlier, LTS 2.277.1 and earlier. See the LTS upgrade guide.
Пакеты
Наименование
de.einsundeins.jenkins.plugins.failedjobdeactivator:failedJobDeactivator
maven
Затронутые версииВерсия исправления
<= 1.2.1
Отсутствует
Связанные уязвимости
CVSS3: 4.3
nvd
больше 3 лет назад
A cross-site request forgery (CSRF) vulnerability in Jenkins Failed Job Deactivator Plugin 1.2.1 and earlier allows attackers to disable jobs.