GHSA-hgpq-42pf-9vfq
MODERATECVE-2022-30953A cross-site request forgery (CSRF) vulnerability in Jenkins Blue Ocean Plugin 1.25.3 and earlier allows attackers to connect to an attacker-specified HTTP server. Blue Ocean Plugin 1.25.4 requires POST requests and the appropriate permissions for the affected HTTP endpoints.
- Affected
- < 1.25.4
- Fixed in
- 1.25.4
- Weakness
- CWE-352
- Published
- 2022-05-18
- Source
- github