A cross-site request forgery vulnerability exists in Jenkins Git Plugin 3.9.1 and earlier in src/main/java/hudson/plugins/git/GitTagAction.java that allows attackers to create a Git tag in a workspace and attach corresponding metadata to a build record.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published: 2019-02-06T16:00:00

Updated: 2024-08-05T03:00:19.322Z

Reserved: 2019-02-06T00:00:00

Link: CVE-2019-1003010

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-02-06T16:29:00.563

Modified: 2019-04-26T14:01:56.520

Link: CVE-2019-1003010

cve-icon Redhat

Severity : Low

Publid Date: 2019-01-28T00:00:00Z

Links: CVE-2019-1003010 - Bugzilla