CVE-2019-1003010

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
06/02/2019
Last modified:
26/04/2019

Description

A cross-site request forgery vulnerability exists in Jenkins Git Plugin 3.9.1 and earlier in src/main/java/hudson/plugins/git/GitTagAction.java that allows attackers to create a Git tag in a workspace and attach corresponding metadata to a build record.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jenkins:git:*:*:*:*:*:jenkins:*:* 3.9.1 (including)
cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*