cbcvebase.
CVE-2023-49673
published 2023-11-29

CVE-2023-49673: A cross-site request forgery (CSRF) vulnerability in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers to connect to an…

high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
A cross-site request forgery (CSRF) vulnerability in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers to connect to an attacker-specified hostname and port using attacker-specified username and password.

Affected

8 ranges
VendorProductVersion rangeFixed in
jenkinsgoogle_compute_engine< 4.551.04.551.0
jenkinsgoogle_compute_engine_plugin
jenkinsjira< 3.1.23.1.2
jenkinsjira_plugin
jenkinsmatlab< 2.11.12.11.1
jenkinsmatlab_plugin
jenkinsneuvector_vulnerability_scanner< 2.22.2
jenkins_projectjenkins_neuvector_vulnerability_scanner_plugin<= 1.22