PT-2023-3358 · Jenkins · Jenkins Reverse Proxy Auth Plugin+1

·

CVE-2023-32987

·

Published

2023-05-16

·

Updated

2023-05-25

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Jenkins Reverse Proxy Auth Plugin versions 1.7.4 and earlier
Description The issue is related to a cross-site request forgery (CSRF) vulnerability. This vulnerability allows attackers to connect to an attacker-specified LDAP server using attacker-specified credentials. The exploitation of this issue may enable an attacker to perform a CSRF attack.
Recommendations For Jenkins Reverse Proxy Auth Plugin versions 1.7.4 and earlier, update to version 1.7.5 or later, which requires POST requests for the affected form validation method, thus mitigating the CSRF vulnerability.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-03514
CVE-2023-32987
GHSA-PMMR-R9V2-59P8

Affected Products

Jenkins
Jenkins Reverse Proxy Auth Plugin