CSRF vulnerability and missing permission checks in Code Dx Plugin
CVE-2023-2195
4.3MEDIUM
Key Information:
- Vendor
Jenkins
- Status
- Vendor
- CVE Published:
- 16 May 2023
What is CVE-2023-2195?
A cross-site request forgery (CSRF) vulnerability in Jenkins Code Dx Plugin 3.1.0 and earlier allows attackers to connect to an attacker-specified URL.
Affected Version(s)
Jenkins Code Dx Plugin 0 <= 3.1.0