Jenkins GitHub Integration Plugin
cpe:2.3:a:jenkins:github_pull_request_builder:*:*:*:*:jenkins:*:*
- <= 0.7.3
A cross-site request forgery (CSRF) vulnerability exists in Jenkins GitHub Integration Plugin versions through 0.7.3. This vulnerability allows attackers to trigger builds for pull requests by exploiting the lack of proper request validation.
Exploitation of this vulnerability allows for unauthorized triggering of builds on Jenkins pull requests, potentially leading to unintended code execution or integration issues.
Users of Jenkins GitHub Integration Plugin should update to version 0.7.4, which addresses this vulnerability by requiring POST requests for the affected HTTP endpoint.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.