CVE-2019-16548: CSRF
A cross-site request forgery vulnerability in Jenkins Google Compute Engine Plugin 4.1.1 and earlier in ComputeEngineCloud#doProvision could be used to provision new agents.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-16548?
The severity of CVE-2019-16548 is high with a severity value of 8.8.
What is the description of CVE-2019-16548?
CVE-2019-16548 is a cross-site request forgery vulnerability in Jenkins Google Compute Engine Plugin that allows the provisioning of new agents.
How does CVE-2019-16548 affect Jenkins Google Compute Engine Plugin?
CVE-2019-16548 affects Jenkins Google Compute Engine Plugin version 4.1.1 and earlier in ComputeEngineCloud#doProvision.
How can I fix the vulnerability CVE-2019-16548 in Jenkins Google Compute Engine Plugin?
To fix the vulnerability CVE-2019-16548, update Jenkins Google Compute Engine Plugin to version 4.2.0 or later.
Are there any references for CVE-2019-16548?
Yes, you can find references for CVE-2019-16548 at the following links: [Link 1](http://www.openwall.com/lists/oss-security/2019/11/21/1), [Link 2](https://jenkins.io/security/advisory/2019-11-21/#SECURITY-1586).