QID 996967
Date Published: 2024-01-31
QID 996967: Java (Maven) Security Update for io.jenkins.plugins:frugal-testing (GHSA-g6rx-2w84-xmgj)
A cross-site request forgery (CSRF) vulnerability in Jenkins Frugal Testing Plugin 1.1 and earlier allows attackers to connect to Frugal Testing using attacker-specified credentials, and to retrieve test IDs and names from Frugal Testing, if a valid credential corresponds to the attacker-specified username.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-g6rx-2w84-xmgj for updates and patch information.
Vendor References
- GHSA-g6rx-2w84-xmgj -
github.com/advisories/GHSA-g6rx-2w84-xmgj
CVEs related to QID 996967
Software Advisories
| Advisory ID | Software | Component | Link |
|---|