-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The commit diff shows two critical changes to the doTestConnection method: 1) Added @POST annotation to enforce HTTP POST requests, indicating previous CSRF vulnerability. 2) Added permission checks (Jenkins.ADMINISTER/Item.CONFIGURE) that were previously missing. The vulnerability description explicitly mentions these two flaws - CSRF vulnerability and missing permission checks in a form validation endpoint, which matches the pre-patch implementation of this connection test method.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:slack | maven | <= 2.19 | 2.20 |
Ongoing coverage of React2Shell