Vulnerabilities > Jenkins > Jenkins Reviewbot
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-04-04 | CVE-2019-10279 | Missing Authorization vulnerability in Jenkins Jenkins-Reviewbot A missing permission check in Jenkins jenkins-reviewbot Plugin in the ReviewboardDescriptor#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server. | 6.5 |
2019-04-04 | CVE-2019-10278 | Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Jenkins-Reviewbot A cross-site request forgery vulnerability in Jenkins jenkins-reviewbot Plugin in the ReviewboardDescriptor#doTestConnection form validation method allows attackers to initiate a connection to an attacker-specified server. | 6.5 |