A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Integration Plugin 0.7.3 and earlier allows attackers to attackers to trigger a build for a pull request.
Metrics
Affected Vendors & Products
References
History
Thu, 28 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kostyasha
Kostyasha github Integration |
|
| CPEs | cpe:2.3:a:kostyasha:github_integration:*:*:*:*:*:jenkins:*:* | |
| Vendors & Products |
Kostyasha
Kostyasha github Integration |
Wed, 27 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | CSRF Vulnerability Allows Unauthorized Build Trigger in Jenkins GitHub Integration Plugin |
Wed, 27 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-352 | |
| Metrics |
cvssV3_1
|
Wed, 27 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Integration Plugin 0.7.3 and earlier allows attackers to attackers to trigger a build for a pull request. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published: 2026-05-27T14:13:51.969Z
Updated: 2026-05-27T15:22:16.078Z
Reserved: 2026-05-26T14:50:46.813Z
Link: CVE-2026-48925
Updated: 2026-05-27T15:22:09.588Z
Status : Analyzed
Published: 2026-05-27T15:16:32.190
Modified: 2026-05-28T16:57:40.600
Link: CVE-2026-48925
No data.