GHSA-48g9-h7g5-8pw2
HIGHCVE-2023-28676Convert To Pipeline Plugin 1.0 and earlier does not require POST requests for the HTTP endpoint converting a Freestyle project to Pipeline, resulting in a cross-site request forgery (CSRF) vulnerability.
- Affected
- <= 1.0
- Fixed in
- not stated
- Weakness
- CWE-352
- Published
- 2023-04-02
- Source
- github