Jenkins Lucene-Search Plugin 387.v938a_ecb_f7fe9 and earlier does not require POST requests for an HTTP endpoint, allowing attackers to reindex the database.
2023-04-12T18:15:12.197
2025-02-07T19:15:24.007
Modified
CVSSv3.1: 4.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | jenkins | lucene-search | ≤ 387.v938a_ecb_f7fe9 | Yes |