Cross-Site Request Forgery Vulnerability in Jenkins Blue Ocean Plugin by Jenkins
CVE-2023-40341
8.8HIGH
What is CVE-2023-40341?
A cross-site request forgery (CSRF) issue in the Jenkins Blue Ocean Plugin versions up to 1.27.5 enables attackers to exploit the plugin's functionality. By tricking users into making a request to an attacker-specified URL, this vulnerability can lead to unauthorized access to sensitive GitHub credentials associated with specific jobs in Jenkins. This poses significant risks for users who may inadvertently expose their credentials, allowing for potential misuse of access to repositories.
Affected Version(s)
Jenkins Blue Ocean Plugin 1.27.5.1
Jenkins Blue Ocean Plugin 1.27.5.1
Jenkins Blue Ocean Plugin 1.27.4.1