Cross-Site Request Forgery in Jenkins Folders Plugin Affects Jenkins
CVE-2023-40336

8.8HIGH

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
16 August 2023

Summary

A cross-site request forgery (CSRF) vulnerability has been identified in Jenkins Folders Plugin, specifically affecting versions 6.846.v23698686f0f6 and earlier. This vulnerability allows unauthorized attackers to exploit the system by copying folders without appropriate user consent. It highlights the importance of implementing security measures to prevent CSRF attacks in Jenkins environments and protect sensitive data from being manipulated.

Affected Version(s)

Jenkins Folders Plugin 0 <= 6.846.v23698686f0f6

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.