Cross-Site Request Forgery in Jenkins AppSpider Plugin
CVE-2023-32998
8.8HIGH
What is CVE-2023-32998?
A cross-site request forgery (CSRF) vulnerability in the Jenkins AppSpider Plugin allows attackers to manipulate user sessions. Specifically, the flaw enables threat actors to connect to a configured malicious URL and send crafted HTTP POST requests that might include unauthorized JSON payloads with credentials specified by the attacker. This vulnerability can lead to unauthorized access and actions being taken on behalf of vulnerable users, potentially compromising the security of Jenkins environments.
Affected Version(s)
Jenkins AppSpider Plugin 0 <= 1.0.15