Cross-Site Request Forgery in Jenkins Folders Plugin
CVE-2023-40337

4.3MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
16 August 2023

Summary

The Jenkins Folders Plugin is susceptible to a cross-site request forgery (CSRF) vulnerability, which can be exploited by attackers to perform unauthorized actions, such as copying views within a folder. This could lead to a breach of access controls and unauthorized manipulation of sensitive data. Users are advised to upgrade to the latest version to mitigate potential risks. For detailed information and guidance, visit the Jenkins Security Advisory.

Affected Version(s)

Jenkins Folders Plugin 0 <= 6.846.v23698686f0f6

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.