Description
A cross-site request forgery (CSRF) vulnerability in Jenkins Jianliao Notification Plugin 1.1 and earlier allows attackers to send HTTP POST requests to an attacker-specified URL.
Remediation
References
https://www.jenkins.io/security/advisory/2022-06-22/#SECURITY-2240
Related Vulnerabilities
CVE-2016-3674 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2021-22096 Vulnerability in maven package org.springframework:spring-webflux
CVE-2020-2194 Vulnerability in maven package io.jenkins.plugins:echarts-api
CVE-2018-14042 Vulnerability in maven package org.webjars.npm:bootstrap-sass
CVE-2022-34197 Vulnerability in maven package org.jenkins-ci.plugins:sauce-ondemand