A cross-site request forgery (CSRF) vulnerability in Jenkins HTMLResource Plugin 1.02 and earlier allows attackers to delete arbitrary files on the Jenkins controller file system.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "1.01"
},
{
"introduced": "0"
},
{
"last_affected": "1.02"
}
]
}