Description
Jenkins Release Plugin 2.9 and earlier did not require form submissions to be submitted via POST, resulting in a CSRF vulnerability allowing attackers to trigger release builds.
Remediation
References
http://www.securityfocus.com/bid/102834
https://jenkins.io/security/advisory/2018-01-22/
Related Vulnerabilities
CVE-2015-7940 Vulnerability in maven package org.bouncycastle:bcprov-ext-jdk14
CVE-2019-1003059 Vulnerability in maven package org.jvnet.hudson.plugins:ftppublisher
CVE-2021-41164 Vulnerability in maven package org.webjars.npm:ckeditor4
CVE-2015-2913 Vulnerability in maven package com.orientechnologies:orientdb-server
CVE-2020-2119 Vulnerability in maven package org.jenkins-ci.plugins:azure-ad