Cross-Site Request Forgery Vulnerability in Jenkins vSphere Plugin by CloudBees
CVE-2018-1000153
8.8HIGH
What is CVE-2018-1000153?
A cross-site request forgery vulnerability exists in the Jenkins vSphere Plugin in versions up to 2.16. This flaw allows attackers to manipulate form submissions, enabling them to send an excessive number of requests to the configured vSphere server, potentially resulting in a denial of service. Additionally, the vulnerability may expose credentials stored in Jenkins to a server specified by the attacker.