Cross-Site Request Forgery Vulnerability in Jenkins Nexus Platform Plugin
CVE-2023-50766

8.8HIGH

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
13 December 2023

What is CVE-2023-50766?

A cross-site request forgery (CSRF) vulnerability exists in the Jenkins Nexus Platform Plugin, specifically in versions 3.18.0-03 and earlier. This flaw allows attackers to manipulate user requests to send malicious HTTP requests to user-defined URLs, potentially leading to unauthorized actions and data manipulation. The vulnerability enables the parsing of the response as XML, which could be leveraged in further exploitations. Users of the affected versions are advised to update to secure versions as recommended in the Jenkins security advisory.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Jenkins Nexus Platform Plugin 0 <= 3.18.0-03

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.