Cross-Site Request Forgery Vulnerability in Jenkins Reverse Proxy Auth Plugin by Jenkins
CVE-2023-32987
8.8HIGH
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 16 May 2023
What is CVE-2023-32987?
The Jenkins Reverse Proxy Auth Plugin version 1.7.4 and earlier is susceptible to a cross-site request forgery (CSRF) vulnerability. This flaw allows attackers to send requests that can connect to an attacker-specified LDAP server by using attacker-provided credentials. Such exploitation can lead to unauthorized access and control over user accounts, making it critical for users of the plugin to ensure their systems are updated and configured properly.
Affected Version(s)
Jenkins Reverse Proxy Auth Plugin 0 <= 1.7.4