Intent-Code Divergence
Medium
- Confidence
- 90% confidence
- Finding
- The documentation states that creating a Jenkins server can be performed via GET/POST, which exposes a state-changing operation through a method commonly assumed to be safe and cacheable. This can enable accidental triggering, CSRF exposure, unsafe prefetching by browsers or intermediaries, and inconsistent client behavior around a privileged administrative action.
