A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and earlier, LTS 2.319.1 and earlier allows attackers to trigger build of job without parameters when no security realm is set.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "2.319.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.329"
}
]
}