漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
漏洞
N/A
漏洞信息
Poll SCM Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks. This allowed attackers to initiate polling of projects with a known name. While Jenkins in general does not consider polling to be a protection-worthy action as it's similar to cache invalidation, the plugin specifically adds a permission to be able to use this functionality, and this issue undermines that permission.
漏洞信息
N/A
漏洞
N/A
漏洞
CloudBees Poll SCM插件跨站请求伪造漏洞
漏洞信息
CloudBees Poll SCM Plugin是美国CloudBees公司的Jenkins(基于Java开发的持续集成工具)中的一个定时执行插件。 CloudBees Poll SCM插件存在跨站请求伪造漏洞,该漏洞源于程序没有要求使用POST请求来向API发送请求。远程攻击者可利用该漏洞轮询项目。
漏洞信息
N/A
漏洞
N/A