Cross-site request forgery in Warnings - CVE-2020-2280
Published: September 23, 2020 / Updated: September 30, 2020
Warnings
Jenkins
Description
The vulnerability allows a remote attacker to perform cross-site request forgery attacks.
The vulnerability exists due to the affected plugin does not require POST requests for a form validation method intended for testing custom warnings parsers. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website.