PT-2023-3358 · Jenkins · Jenkins Reverse Proxy Auth Plugin+1

·

CVE-2023-32987

·

Publicado

2023-05-16

·

Atualizado

2023-05-25

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Jenkins Reverse Proxy Auth Plugin versions 1.7.4 and earlier
Description The issue is related to a cross-site request forgery (CSRF) vulnerability. This vulnerability allows attackers to connect to an attacker-specified LDAP server using attacker-specified credentials. The exploitation of this issue may enable an attacker to perform a CSRF attack.
Recommendations For Jenkins Reverse Proxy Auth Plugin versions 1.7.4 and earlier, update to version 1.7.5 or later, which requires POST requests for the affected form validation method, thus mitigating the CSRF vulnerability.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-03514
CVE-2023-32987
GHSA-PMMR-R9V2-59P8

Produtos afetados

Jenkins
Jenkins Reverse Proxy Auth Plugin