Cross-Site Request Forgery in Jenkins Google Compute Engine Plugin
CVE-2019-16548
8.8HIGH
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 21 November 2019
What is CVE-2019-16548?
A cross-site request forgery vulnerability exists in the Jenkins Google Compute Engine Plugin version 4.1.1 and earlier. This flaw allows unauthorized provisioning of new agents through the ComputeEngineCloud#doProvision method, posing a potential risk to the system's integrity and operation.
Affected Version(s)
Jenkins Google Compute Engine Plugin 4.1.1 and earlier