Cross-Site Request Forgery Vulnerability in Jenkins Nexus Platform Plugin
CVE-2023-50766
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 13 December 2023
What is CVE-2023-50766?
A cross-site request forgery (CSRF) vulnerability exists in the Jenkins Nexus Platform Plugin, specifically in versions 3.18.0-03 and earlier. This flaw allows attackers to manipulate user requests to send malicious HTTP requests to user-defined URLs, potentially leading to unauthorized actions and data manipulation. The vulnerability enables the parsing of the response as XML, which could be leveraged in further exploitations. Users of the affected versions are advised to update to secure versions as recommended in the Jenkins security advisory.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins Nexus Platform Plugin 0 <= 3.18.0-03
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved