A cross-site request forgery vulnerability exists in Jenkins Git Plugin 3.9.1 and earlier in src/main/java/hudson/plugins/git/GitTagAction.java that allows attackers to create a Git tag in a workspace and attach corresponding metadata to a build record.
{
"severity": "MODERATE",
"nvd_published_at": "2019-02-06T16:29:00Z",
"github_reviewed_at": "2022-06-29T15:02:39Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-352"
]
}