CVE-2024-28158
Description
A CSRF vulnerability in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers to trigger builds without authorization.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A CSRF vulnerability in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers to trigger builds without authorization.
The Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier is vulnerable to cross-site request forgery (CSRF). This flaw occurs because the plugin does not require a confirmation token or other CSRF protection when processing requests to trigger builds [1]. Attackers can exploit this by crafting malicious web pages or links that, when visited by an authenticated Jenkins user with appropriate permissions, cause the user's browser to send an unauthorized request to the Jenkins server [2]. This results in a build being triggered without the user's consent [4]. The impact is that an attacker can force the execution of arbitrary builds, potentially consuming resources or disrupting normal operations. As of the advisory date, no fix is available, and the plugin is listed as an unresolved security issue [2]. Users should consider disabling the plugin if not required until a patch is released.
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:svn-partial-release-mgrMaven | <= 1.0.1 | — |
Affected products
2- Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/advisories/GHSA-rv35-69ff-g9gvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-28158ghsaADVISORY
- www.jenkins.io/security/advisory/2024-03-06/ghsavendor-advisoryWEB
- www.openwall.com/lists/oss-security/2024/03/06/3ghsaWEB
News mentions
1- Jenkins Security Advisory 2024-03-06Jenkins Security Advisories · Mar 6, 2024