cbcvebase.
CVE-2023-37961
published 2023-07-12

CVE-2023-37961: A cross-site request forgery (CSRF) vulnerability in Jenkins Assembla Auth Plugin 1.14 and earlier allows attackers to trick users into logging in to the…

PriorityP336high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.48%
38.3th percentile
A cross-site request forgery (CSRF) vulnerability in Jenkins Assembla Auth Plugin 1.14 and earlier allows attackers to trick users into logging in to the attacker's account.

Affected

17 ranges
VendorProductVersion rangeFixed in
jenkinsactive_directory_plugin
jenkinsassembla<= 1.14
jenkinsassembla_auth_plugin
jenkinsbenchmark_evaluator_plugin
jenkinsdatadog_plugin
jenkinselasticbox_ci_plugin
jenkinsexternal_monitor_job_type_plugin
jenkinsfor_more_information_see_the_plugin
jenkinsmacstadium_plugin
jenkinsmathworks_polyspace_plugin
jenkinsopenshift_login_plugin
jenkinsoracle_cloud_infrastructure_compute_plugin
jenkinsorka_by_macstadium_plugin
jenkinsrebuilder_plugin
jenkinssumologic_publisher_plugin
jenkinstest_results_aggregator_plugin
jenkins_projectjenkins_assembla_auth_plugin<= 1.14
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.