CVE-2019-16550: CSRF
Published Dec 17, 2019
·Updated
A cross-site request forgery vulnerability in a connection test form method in Jenkins Maven Release Plugin 0.16.1 and earlier allows attackers to have Jenkins connect to an attacker specified web server and parse XML documents.
Affected Software
2 affected componentsFixes available
maven/org.jenkins-ci.plugins.m2release:m2release<=0.16.1
0.16.2
Jenkins Maven Jenkins<=0.16.1
Event History
Dec 17, 2019
CVE Published
via MITRE·02:40 PM
Data Sourced
via MITRE·02:40 PM
Description
May 24, 2022
Advisory Published
05:03 PM
Frequently Asked Questions
1
What is the severity of CVE-2019-16550?
CVE-2019-16550 is classified as a Medium severity vulnerability.
2
How do I fix CVE-2019-16550?
To fix CVE-2019-16550, upgrade the Jenkins Maven Release Plugin to version 0.16.2 or later.
3
What type of vulnerability is CVE-2019-16550?
CVE-2019-16550 is a cross-site request forgery (CSRF) vulnerability.
4
What does CVE-2019-16550 allow an attacker to do?
CVE-2019-16550 allows an attacker to have Jenkins connect to an attacker-specified web server.
5
Which versions of Jenkins Maven Plugin are affected by CVE-2019-16550?
Versions of Jenkins Maven Release Plugin up to and including 0.16.1 are affected by CVE-2019-16550.