cbcvebase.
CVE-2023-39153
published 2023-07-26

CVE-2023-39153: A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Authentication Plugin 1.17.1 and earlier allows attackers to trick users into logging in to…

medium5.4CVSS 3.1
AVNACLPRNUIRSUCLILAN
A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Authentication Plugin 1.17.1 and earlier allows attackers to trick users into logging in to the attacker's account.

Affected

14 ranges
VendorProductVersion rangeFixed in
gitlabgitlab
jenkinsbazaar_plugin
jenkinschef_identity_plugin
jenkinsgitlab_authentication<= 1.17.1
jenkinsgitlab_authentication_plugin
jenkinsgradle_plugin
jenkinsincorrect_control_flow_in_gradle_plugin
jenkinsjenkins_core
jenkinsjenkins_lts
jenkinsjenkins_weekly
jenkinsqualys_web_app_scanning_connector_plugin
jenkinssecret_displayed_without_masking_by_chef_identity_plugin
jenkinsservicenow_devops_plugin
jenkins_projectjenkins_gitlab_authentication_plugin<= 1.17.1