Description
Jenkins Release Plugin 2.9 and earlier did not require form submissions to be submitted via POST, resulting in a CSRF vulnerability allowing attackers to trigger release builds.
Remediation
References
http://www.securityfocus.com/bid/102834
https://jenkins.io/security/advisory/2018-01-22/
Related Vulnerabilities
CVE-2022-24814 Vulnerability in npm package directus
CVE-2021-3632 Vulnerability in maven package org.keycloak:keycloak-core
CVE-2017-16157 Vulnerability in npm package censorify.tanisjr
CVE-2021-43116 Vulnerability in maven package com.alibaba.nacos:nacos-client
CVE-2022-39259 Vulnerability in maven package io.github.skylot:jadx-plugins-api