-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The commit diff shows the addition of @POST annotation to doCheckServer method and checkMethod='post' in the Jelly form configuration. This directly addresses the CSRF vulnerability by requiring POST requests for server validation. The advisory explicitly mentions this form validation method as the attack vector.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:ldap | maven | < 676.vfa | 676.vfa |