cbcvebase.
CVE-2023-30529
published 2023-04-12

CVE-2023-30529: Jenkins Lucene-Search Plugin 387.v938a_ecb_f7fe9 and earlier does not require POST requests for an HTTP endpoint, allowing attackers to reindex the database.

PriorityP420medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
0.35%
27.0th percentile
Jenkins Lucene-Search Plugin 387.v938a_ecb_f7fe9 and earlier does not require POST requests for an HTTP endpoint, allowing attackers to reindex the database.

Affected

16 ranges
VendorProductVersion rangeFixed in
jenkinsassembla_merge_request_builder_plugin
jenkinsazure_key_vault_plugin
jenkinsconsul_kv_builder_plugin
jenkinsdelinea_secret_server_platform_plugin
jenkinsfogbugz_plugin
jenkinsimage_tag_parameter_plugin
jenkinskubernetes_plugin
jenkinslack_of_authentication_mechanism_in_fogbugz_plugin
jenkinslack_of_authentication_mechanism_in_turboscript_plugin
jenkinslucene-search<= 387.v938a_ecb_f7fe9
jenkinslucene-search_plugin
jenkinsquay.io_trigger_plugin
jenkinsreport_portal_plugin
jenkinsthycotic_devops_secrets_vault_plugin
jenkinsturboscript_plugin
jenkins_projectjenkins_lucene-search_plugin<= 387.v938a_ecb_f7fe9
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.