CSRF vulnerability and missing permission checks in Code Dx Plugin
CVE-2023-2631
4.3MEDIUM
Key Information:
- Vendor
Jenkins
- Status
- Vendor
- CVE Published:
- 16 May 2023
What is CVE-2023-2631?
A missing permission check in Jenkins Code Dx Plugin 3.1.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.
Affected Version(s)
Jenkins Code Dx Plugin 0 <= 3.1.0