-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:shared-objects | maven | <= 0.44 |
The advisory explicitly states the vulnerability stems from missing POST request requirements for a configuration endpoint. In Jenkins plugin architecture, HTTP endpoints handling configuration typically use do[Action] methods (like doConfigure) in Java classes. The absence of @RequirePOST annotation or equivalent CSRF protection in this method would allow unauthorized state changes via CSRF. This matches the pattern of Jenkins CSRF vulnerabilities where security controls are missing from configuration handlers.