Loading HuntDB...

GHSA-g2x8-xw86-vpq3

GitHub Security Advisory

Cross-site request forgery (CSRF) vulnerability in Jenkins Maven Release Plugin

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

A cross-site request forgery vulnerability in a connection test form method in Jenkins Maven Release Plugin 0.16.1 and earlier allows attackers to have Jenkins connect to an attacker specified web server and parse XML documents.

Affected Packages

Maven org.jenkins-ci.plugins.m2release:m2release
Affected versions: 0 (fixed in 0.16.2)

Related CVEs

Key Information

GHSA ID
GHSA-g2x8-xw86-vpq3
Published
May 24, 2022 5:03 PM
Last Modified
December 14, 2023 6:20 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.plugins.m2release:m2release
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 5, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.