-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from the doNotifyCommit endpoint handler lacking authentication and CSRF protections. The function accepted GET requests without validating() a token parameter, enabling unauthorized build triggering and information disclosure. The commit diff shows security checks were added in GitStatus.java's doNotifyCommit method, confirming this was the vulnerable entry point. The absence of token validation in pre-4.11.4 versions directly maps to CWE-306 (Missing Authentication) and CWE-200 (Information Exposure).
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:git | maven | <= 4.11.3 | 4.11.4 |
Ongoing coverage of React2Shell