CVE Database
/

CVE-2019-10324

Back to search

CVE-2019-10324

Published: May 31, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ReleaseAction#doSubmit, GradleReleaseApiAction#doStaging, MavenReleaseApiAction#doStaging, and UnifiedPromoteBuildAction#doSubmit allowed attackers to schedule a release build, perform release staging for Gradle and Maven projects, and promote previously staged builds, respectively.

VendorProductVersions

Jenkins project

Jenkins Artifactory Plugin

affected
3.2.2 and earlier

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now