Cross-Site Request Forgery Vulnerability in Jenkins Test Results Aggregator Plugin
CVE-2023-37955
6.5MEDIUM
Key Information:
- Vendor
- Jenkins
- Vendor
- CVE Published:
- 12 July 2023
Summary
The Jenkins Test Results Aggregator Plugin is susceptible to a cross-site request forgery (CSRF) vulnerability that enables attackers to initiate actions on behalf of a user without their consent. This vulnerability allows an attacker to send crafted requests that could compel the Jenkins server to connect to malicious URLs utilizing compromised user credentials. This could potentially expose sensitive systems once the attacker gains access through unauthorized means. Users are strongly advised to upgrade to the latest versions of the plugin to mitigate this risk.
Affected Version(s)
Jenkins Test Results Aggregator Plugin 0 <= 1.2.13
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved