-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from an HTTP endpoint that 1) lacks permission checks and 2) accepts GET requests. In Jenkins plugin architecture, HTTP endpoints are typically implemented via 'doXxx' methods in Java classes. The combination of missing security checks (checkPermission) and GET method exposure creates CSRF conditions. The function name and location are inferred from standard plugin patterns and the backup functionality described in advisories.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:google-cloud-backup | maven | <= 0.6 |
Ongoing coverage of React2Shell