Cross-Site Request Forgery in Jenkins Plugin by CloudBees
CVE-2019-10278
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 4 April 2019
What is CVE-2019-10278?
A cross-site request forgery vulnerability exists in the Jenkins jenkins-reviewbot Plugin that allows unauthorized attackers to exploit the ReviewboardDescriptor#doTestConnection method. This vulnerability can lead to attackers initiating connections to a server of their choice without user consent, creating potential privacy and security risks for affected users. It is crucial for plugin users to ensure they are using patched versions to mitigate any risks related to this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins jenkins-reviewbot Plugin all versions as of 2019-04-03
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved