Description
A cross-site request forgery (CSRF) vulnerability in Jenkins Lockable Resources Plugin 2.8 and earlier allows attackers to reserve, unreserve, unlock, and reset resources.
Remediation
References
https://www.jenkins.io/security/advisory/2020-09-23/#SECURITY-1958
http://www.openwall.com/lists/oss-security/2020/09/23/1
Related Vulnerabilities
CVE-2023-27094 Vulnerability in maven package cn.hippo4j:hippo4j-all
CVE-2022-25766 Vulnerability in npm package ungit
CVE-2021-26117 Vulnerability in maven package org.apache.activemq:artemis-server
CVE-2022-34811 Vulnerability in maven package org.jenkins-ci.plugins:xpath-config-viewer
CVE-2023-30543 Vulnerability in npm package @web3-react/coinbase-wallet