CVE-2019-10359: Jenkins m2release

Medium severity, CVSS 6.3. EPSS: 0.6% chance of exploitation in the next 30 days.

A cross-site request forgery vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier in the M2ReleaseAction#doSubmit method allowed attackers to perform releases with attacker-specified options.

Affected products

  • Jenkins m2release: up to and including 0.14.0

Published 2019-07-31. Last modified 2026-06-17.