A cross-site request forgery vulnerability in Jenkins Maven Release Plugin 0.14.0 and previous versions in the M2ReleaseAction#doSubmit method allowed malicious users to perform releases with attacker-specified options.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
jenkins m2release |