Vulnerabilities > Jenkins > Release Helper > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-03-15 | CVE-2022-27214 | Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Release Helper A cross-site request forgery (CSRF) vulnerability in Jenkins Release Helper Plugin 1.3.3 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials. | 4.3 |
2022-03-15 | CVE-2022-27215 | Missing Authorization vulnerability in Jenkins Release Helper A missing permission check in Jenkins Release Helper Plugin 1.3.3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials. | 4.3 |