-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability centers on form validation methods that 1) accepted GET requests (CSRF vector) and 2) lacked admin permission checks. Both NVD and Jenkins advisory explicitly name BlobStoreProfile.DescriptorImpl.doTestConnection and JCloudsCloud.DescriptorImpl.doTestConnection as the vulnerable endpoints. These would be the entry points visible in a profiler during CSRF exploitation attempts. The $DescriptorImpl syntax reflects Java inner classes where form validation methods typically reside in Jenkins plugins.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:jclouds-jenkins | maven | <= 2.14 | 2.15 |
KEV Misses 88% of Exploited CVEs- Get the report