Cross-Site Request Forgery in Jenkins AppSpider Plugin
CVE-2023-32998

8.8HIGH

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
16 May 2023

Summary

A cross-site request forgery (CSRF) vulnerability in the Jenkins AppSpider Plugin allows attackers to manipulate user sessions. Specifically, the flaw enables threat actors to connect to a configured malicious URL and send crafted HTTP POST requests that might include unauthorized JSON payloads with credentials specified by the attacker. This vulnerability can lead to unauthorized access and actions being taken on behalf of vulnerable users, potentially compromising the security of Jenkins environments.

Affected Version(s)

Jenkins AppSpider Plugin 0 <= 1.0.15

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.