GHSA-42mm-x828-56c7
GitHub Security Advisory
CSRF vulnerability in Jenkins Configuration Slicing Plugin
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Jenkins Configuration Slicing Plugin 1.51 and earlier does not require POST requests for the form submission endpoint reconfiguring slices, resulting in a cross-site request forgery (CSRF) vulnerability.
This vulnerability allows attackers to apply different slice configurations to attacker-specified jobs.
Jenkins Configuration Slicing Plugin 1.52 requires POST requests for the affected HTTP endpoint.
Affected Packages
Maven
org.jenkins-ci.plugins:configurationslicing
Affected versions:
0
(fixed in 1.52)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: August 25, 2025 6:33 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.