Loading HuntDB...

GHSA-r4rv-cq77-6p24

GitHub Security Advisory

Jenkins Maven Release Plugin contains Cross-Site Request Forgery vulnerability

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

A cross-site request forgery vulnerability in Jenkins Maven Release Plugin prior to 0.15.0 in the M2ReleaseAction#doSubmit method allowed attackers to perform releases with attacker-specified options.

Affected Packages

Maven org.jenkins-ci.plugins.m2release:m2release
Affected versions: 0 (fixed in 0.15.0)

Related CVEs

Key Information

GHSA ID
GHSA-r4rv-cq77-6p24
Published
May 24, 2022 4:51 PM
Last Modified
February 2, 2023 11:26 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.plugins.m2release:m2release
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 5, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.