Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-71275

doClearCache method can be improved with a POST or RequirePOST annotation.

XMLWordPrintable

      The Jenkins security team doesn't consider the lack of CSRF protection in this method to be a security vulnerability given the impact. This is because the cleanup process happens periodically anyway.

      However, adding a POST or RequirePOST annotation could still improve your plugin and should therefore be considered.

      More information at https://www.jenkins.io/doc/developer/security/form-validation/#protecting-from-csrf

            Unassigned Unassigned
            kevingrdj Kevin Guerroudj
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated: