Artifactory Cross-Site Request Forgery (CSRF) Vulnerability - CVE-2019-10324
Reference:
CVE-2019-10324
Title:
Artifactory Cross-Site Request Forgery (CSRF) Vulnerability
Overview:
A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ReleaseActiondoSubmit GradleReleaseApiActiondoStaging MavenReleaseApiActiondoStaging and UnifiedPromoteBuildActiondoSubmit allowed attackers to schedule a release build perform release staging for Gradle and Maven projects and promote previously staged builds respectively.