CVE-2019-1003010
Severity
4.3MEDIUM
EPSS
0.7%
top 29.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 6
Latest updateMay 14
Description
A cross-site request forgery vulnerability exists in Jenkins Git Plugin 3.9.1 and earlier in src/main/java/hudson/plugins/git/GitTagAction.java that allows attackers to create a Git tag in a workspace and attach corresponding metadata to a build record.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4
Affected Packages2 packages
Also affects: Openshift Container Platform 3.11
🔴Vulnerability Details
3📋Vendor Advisories
3💬Community
1Bugzilla
▶