Cross-site request forgery In org.jenkins-ci.plugins:lucene-search
Description
Jenkins Lucene-Search Plugin vulnerable to Cross-Site Request Forgery Jenkins Lucene-Search Plugin 387.v938a_ecb_f7fe9 and earlier does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery (CSRF) vulnerability.
This vulnerability allows attackers to reindex the database.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 398.v3dfa_cb_223984 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4.