Cross-Site Request Forgery Vulnerability in Jenkins Nexus Platform Plugin
CVE-2023-50766
8.8HIGH
Key Information:
- Vendor
- Jenkins
- Vendor
- CVE Published:
- 13 December 2023
Summary
A cross-site request forgery (CSRF) vulnerability exists in the Jenkins Nexus Platform Plugin, specifically in versions 3.18.0-03 and earlier. This flaw allows attackers to manipulate user requests to send malicious HTTP requests to user-defined URLs, potentially leading to unauthorized actions and data manipulation. The vulnerability enables the parsing of the response as XML, which could be leveraged in further exploitations. Users of the affected versions are advised to update to secure versions as recommended in the Jenkins security advisory.
Affected Version(s)
Jenkins Nexus Platform Plugin 0 <= 3.18.0-03
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved