Description
A cross-site request forgery vulnerability in a connection test form method in Jenkins Maven Release Plugin 0.16.1 and earlier allows attackers to have Jenkins connect to an attacker specified web server and parse XML documents.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/12/17/1
https://jenkins.io/security/advisory/2019-12-17/#SECURITY-1681
Related Vulnerabilities
CVE-2018-20843 Vulnerability in npm package dbus
CVE-2013-7381 Vulnerability in npm package libnotify
CVE-2019-1003056 Vulnerability in maven package org.jenkins-ci.plugins:websphere-deployer
CVE-2022-36031 Vulnerability in npm package directus
CVE-2020-11619 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind