A cross-site request forgery (CSRF) vulnerability in Jenkins Failed Job Deactivator Plugin 1.2.1 and earlier allows attackers to disable jobs. This CSRF vulnerability is only exploitable in Jenkins 2.286 and earlier, LTS 2.277.1 and earlier. See the LTS upgrade guide.
{ "nvd_published_at": "2022-06-30T18:15:00Z", "github_reviewed_at": "2022-07-12T18:14:08Z", "severity": "MODERATE", "github_reviewed": true, "cwe_ids": [ "CWE-352" ] }