CVE-2023-37964
published 2023-07-12CVE-2023-37964: A cross-site request forgery (CSRF) vulnerability in Jenkins ElasticBox CI Plugin 5.0.1 and earlier allows attackers to connect to an attacker-specified URL…
high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
A cross-site request forgery (CSRF) vulnerability in Jenkins ElasticBox CI Plugin 5.0.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | active_directory_plugin | — | — |
| jenkins | assembla_auth_plugin | — | — |
| jenkins | benchmark_evaluator_plugin | — | — |
| jenkins | datadog_plugin | — | — |
| jenkins | elasticbox_ci | <= 5.0.1 | — |
| jenkins | elasticbox_ci_plugin | — | — |
| jenkins | external_monitor_job_type_plugin | — | — |
| jenkins | for_more_information_see_the_plugin | — | — |
| jenkins | macstadium_plugin | — | — |
| jenkins | mathworks_polyspace_plugin | — | — |
| jenkins | openshift_login_plugin | — | — |
| jenkins | oracle_cloud_infrastructure_compute_plugin | — | — |
| jenkins | orka_by_macstadium_plugin | — | — |
| jenkins | rebuilder_plugin | — | — |
| jenkins | sumologic_publisher_plugin | — | — |
| jenkins | test_results_aggregator_plugin | — | — |
| jenkins_project | jenkins_elasticbox_ci_plugin | <= 5.0.1 | — |