CVE-2019-1003010

Severity
4.3MEDIUM
EPSS
0.7%
top 29.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 6
Latest updateMay 14

Description

A cross-site request forgery vulnerability exists in Jenkins Git Plugin 3.9.1 and earlier in src/main/java/hudson/plugins/git/GitTagAction.java that allows attackers to create a Git tag in a workspace and attach corresponding metadata to a build record.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

NVDjenkins/git3.9.1

Also affects: Openshift Container Platform 3.11

🔴Vulnerability Details

3
OSV
Cross-Site Request Forgery in Jenkins Git Plugin2022-05-14
GHSA
Cross-Site Request Forgery in Jenkins Git Plugin2022-05-14
CVEList
CVE-2019-1003010: A cross-site request forgery vulnerability exists in Jenkins Git Plugin 32019-02-06

📋Vendor Advisories

3
Microsoft
A cross-site request forgery vulnerability exists in Jenkins Git Plugin 3.9.1 and earlier2019-02-12
Jenkins
Jenkins Security Advisory 2019-01-282019-01-28
Red Hat
jenkins-plugin-git: CSRF vulnerability in Git Plugin (SECURITY-1095)2019-01-28

💬Community

1
Bugzilla
CVE-2019-1003010 jenkins-plugin-git: CSRF vulnerability in Git Plugin (SECURITY-1095)2019-01-29
CVE-2019-1003010 (MEDIUM CVSS 4.3) | A cross-site request forgery vulner | cvebase.io