Cross-Site Request Forgery Vulnerability in Jenkins Reverse Proxy Auth Plugin by Jenkins
CVE-2023-32987
8.8HIGH
Key Information:
- Vendor
- Jenkins
- Vendor
- CVE Published:
- 16 May 2023
Summary
The Jenkins Reverse Proxy Auth Plugin version 1.7.4 and earlier is susceptible to a cross-site request forgery (CSRF) vulnerability. This flaw allows attackers to send requests that can connect to an attacker-specified LDAP server by using attacker-provided credentials. Such exploitation can lead to unauthorized access and control over user accounts, making it critical for users of the plugin to ensure their systems are updated and configured properly.
Affected Version(s)
Jenkins Reverse Proxy Auth Plugin 0 <= 1.7.4
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved