cbcvebase.
CVE-2023-30525
published 2023-04-12

CVE-2023-30525: A cross-site request forgery (CSRF) vulnerability in Jenkins Report Portal Plugin 0.5 and earlier allows attackers to connect to an attacker-specified URL…

PriorityP340high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.78%
51.7th percentile
A cross-site request forgery (CSRF) vulnerability in Jenkins Report Portal Plugin 0.5 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified bearer token authentication.

Affected

16 ranges
VendorProductVersion rangeFixed in
jenkinsassembla_merge_request_builder_plugin
jenkinsazure_key_vault_plugin
jenkinsconsul_kv_builder_plugin
jenkinsdelinea_secret_server_platform_plugin
jenkinsfogbugz_plugin
jenkinsimage_tag_parameter_plugin
jenkinskubernetes_plugin
jenkinslack_of_authentication_mechanism_in_fogbugz_plugin
jenkinslack_of_authentication_mechanism_in_turboscript_plugin
jenkinslucene-search_plugin
jenkinsquay.io_trigger_plugin
jenkinsreport_portal<= 0.5
jenkinsreport_portal_plugin
jenkinsthycotic_devops_secrets_vault_plugin
jenkinsturboscript_plugin
jenkins_projectjenkins_report_portal_plugin<= 0.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.