Cross-Site Request Forgery Vulnerability in Jenkins mabl Plugin
CVE-2023-37952
What is CVE-2023-37952?
A cross-site request forgery (CSRF) vulnerability in the Jenkins mabl Plugin versions 0.0.46 and earlier exposes users to significant security risks. This flaw allows attackers to execute requests using credentials they have obtained from other methods, potentially gaining access to sensitive information stored within Jenkins. By exploiting this vulnerability, an attacker could direct the Jenkins server to connect to a URL of their choosing, using the compromised user credentials. It's crucial for users of the mabl Plugin to update to the latest version to mitigate the effects of this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins mabl Plugin 0 <= 0.0.46
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved