CVE-2023-32980

Severity
4.3MEDIUM
EPSS
0.1%
top 77.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 16

Description

A cross-site request forgery (CSRF) vulnerability in Jenkins Email Extension Plugin allows attackers to make another user stop watching an attacker-specified job.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

🔴Vulnerability Details

3
GHSA
Jenkins Email Extension Plugin Cross-Site Request Forgery vulnerability2023-05-16
OSV
Jenkins Email Extension Plugin Cross-Site Request Forgery vulnerability2023-05-16
CVEList
CVE-2023-32980: A cross-site request forgery (CSRF) vulnerability in Jenkins Email Extension Plugin allows attackers to make another user stop watching an attacker-sp2023-05-16

📋Vendor Advisories

2
Red Hat
jenkins-2-plugin: email-ext: CSRF vulnerability in Email Extension Plugin2023-05-16
Jenkins
Jenkins Security Advisory 2023-05-162023-05-16
CVE-2023-32980 (MEDIUM CVSS 4.3) | A cross-site request forgery (CSRF) | cvebase.io