Description
A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ReleaseAction#doSubmit, GradleReleaseApiAction#doStaging, MavenReleaseApiAction#doStaging, and UnifiedPromoteBuildAction#doSubmit allowed attackers to schedule a release build, perform release staging for Gradle and Maven projects, and promote previously staged builds, respectively.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4610 | A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ReleaseAction#doSubmit, GradleReleaseApiAction#doStaging, MavenReleaseApiAction#doStaging, and UnifiedPromoteBuildAction#doSubmit allowed attackers to schedule a release build, perform release staging for Gradle and Maven projects, and promote previously staged builds, respectively. |
Github GHSA |
GHSA-mqj3-fc39-73fj | Cross-site request forgery vulnerability in Jenkins Artifactory Plugin |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-04T22:17:20.451Z
Reserved: 2019-03-29T00:00:00.000Z
Link: CVE-2019-10324
No data.
Status : Modified
Published: 2019-05-31T15:29:00.357
Modified: 2024-11-21T04:18:53.590
Link: CVE-2019-10324
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA