Cross-Site Request Forgery Vulnerability in Jenkins Test Results Aggregator Plugin
CVE-2023-37955
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 12 July 2023
What is CVE-2023-37955?
The Jenkins Test Results Aggregator Plugin is susceptible to a cross-site request forgery (CSRF) vulnerability that enables attackers to initiate actions on behalf of a user without their consent. This vulnerability allows an attacker to send crafted requests that could compel the Jenkins server to connect to malicious URLs utilizing compromised user credentials. This could potentially expose sensitive systems once the attacker gains access through unauthorized means. Users are strongly advised to upgrade to the latest versions of the plugin to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins Test Results Aggregator Plugin 0 <= 1.2.13
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved