CVE-2019-10324
31.05.2019, 15:29
A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ReleaseAction#doSubmit, GradleReleaseApiAction#doStaging, MavenReleaseApiAction#doStaging, and UnifiedPromoteBuildAction#doSubmit allowed attackers to schedule a release build, perform release staging for Gradle and Maven projects, and promote previously staged builds, respectively.
Vendor | Product | Version |
---|---|---|
jfrog | artifactory | 𝑥 ≤ 3.2.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References