-
CVSS Score
-The CVE description explicitly identifies DbAuditPublisherDescriptorImpl#doTestJdbcConnection as the vulnerable method. The advisory states it lacks both permission checks (allowing low-privileged users to trigger connections) and CSRF protections (no POST requirement). This matches the CWE-352 (CSRF) classification and the attack vector described in Jenkins' security advisory.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:audit2db | maven | <= 0.5 |
A Semantic Attack on Google Gemini - Read the Latest Research