A cross-site request forgery vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier in the M2ReleaseAction#doSubmit method allowed attackers to perform releases with attacker-specified options.
2019-07-31T13:15:12.683
2024-11-21T04:18:57.983
Modified
CVSSv3.1: 6.3 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4