HIGH
Jenkins Translation Assistance Plugin 1.15 and earlier did not require form submissions to be submitted via POST, resulting in a CSRF vulnerability allowing attackers to override localized strings displayed to all users on the current Jenkins instance if the victim is a Jenkins administrator
Published Jan 23, 2018
8.8
HIGHCVSS 3.0
EPSS 0.83%
Description
Affected products
Remediation
References (4)
Change history (0)
No recorded changes yet.