Description
A cross-site request forgery vulnerability in Jenkins CVS Plugin 2.15 and earlier allows attackers to create and manipulate tags, and to connect to an attacker-specified URL.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/05/06/3
https://jenkins.io/security/advisory/2020-05-06/#SECURITY-1094
Related Vulnerabilities
CVE-2019-1003028 Vulnerability in maven package org.jenkins-ci.plugins:jms-messaging
CVE-2022-29251 Vulnerability in maven package org.xwiki.platform:xwiki-platform-flamingo-theme-ui
CVE-2022-23458 Vulnerability in npm package tui-grid
CVE-2019-18212 Vulnerability in maven package org.lsp4xml:lsp4xml-extensions