Cross-Site Request Forgery Vulnerability in Jenkins Nexus Platform Plugin
CVE-2023-50766
8.8HIGH
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 13 December 2023
What is CVE-2023-50766?
A cross-site request forgery (CSRF) vulnerability exists in the Jenkins Nexus Platform Plugin, specifically in versions 3.18.0-03 and earlier. This flaw allows attackers to manipulate user requests to send malicious HTTP requests to user-defined URLs, potentially leading to unauthorized actions and data manipulation. The vulnerability enables the parsing of the response as XML, which could be leveraged in further exploitations. Users of the affected versions are advised to update to secure versions as recommended in the Jenkins security advisory.
Affected Version(s)
Jenkins Nexus Platform Plugin 0 <= 3.18.0-03