Cross-Site Request Forgery Vulnerability in Jenkins PaaSLane Estimate Plugin
CVE-2023-50778
8.8HIGH
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 13 December 2023
What is CVE-2023-50778?
A cross-site request forgery (CSRF) vulnerability exists in the Jenkins PaaSLane Estimate Plugin version 1.0.4 and earlier. This flaw permits attackers to connect to a URL specified by them, utilizing an attacker-defined token, which could lead to unauthorized actions being executed on behalf of unsuspecting users.
Affected Version(s)
Jenkins PaaSLane Estimate Plugin 0 <= 1.0.4