A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and earlier, LTS 2.319.1 and earlier allows attackers to trigger build of job without parameters when no security realm is set.
2022-01-12T20:15:08.653
2024-11-21T06:43:09.423
Modified
CVSSv3.1: 4.3 (MEDIUM)
AV:N/AC:H/Au:N/C:N/I:P/A:N
4.9
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | jenkins | jenkins | ≤ 2.319.1 | Yes |
| Application | jenkins | jenkins | ≤ 2.329 | Yes |
| Application | oracle | communications_cloud_native_core_automated_test_suite | 1.9.0 | Yes |