CVE-2019-10324: CSRF
A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ReleaseAction#doSubmit, GradleReleaseApiAction#doStaging, MavenReleaseApiAction#doStaging, and UnifiedPromoteBuildAction#doSubmit allowed attackers to schedule a release build, perform release staging for Gradle and Maven projects, and promote previously staged builds, respectively.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-10324.
What is the severity of CVE-2019-10324?
The severity of CVE-2019-10324 is medium.
Which software versions are affected by CVE-2019-10324?
Jfrog Artifactory versions up to and including 3.2.2 are affected by CVE-2019-10324.
How can attackers exploit CVE-2019-10324?
Attackers can exploit CVE-2019-10324 to schedule a release build, perform release staging, and promote a build.
Are there any references for more information about CVE-2019-10324?
Yes, you can find more information about CVE-2019-10324 at the following references: [link1](http://www.openwall.com/lists/oss-security/2019/05/31/2), [link2](http://www.securityfocus.com/bid/108540), [link3](https://jenkins.io/security/advisory/2019-05-31/#SECURITY-1347).