📦

poll_scm

Vendor: jenkins

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 17 Total Indexed
Avg. EPSS 0.06% Exploit Prob.
Latest CVE CVE-2017-1000093 Oct 05

Security Vulnerability Index

Page 1 / 2
8.8 CVSS

Poll SCM Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks. This allowed attackers to initiate polling of projects with a known name. While Jenkins in general does not consider polling to be a protection-worthy action as it's similar to cache invalidation, the plugin specifically adds a permission to be able to use this functionality, and this issue undermines that permission.

EPSS: 0.06%