Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-35148

Опубликовано: 14 июн. 2023
Источник: redhat
CVSS3: 4.2

Описание

A cross-site request forgery (CSRF) vulnerability in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers to connect to an attacker-specified URL, capturing credentials stored in Jenkins.

Отчет

The Jenkins Digital.ai App Management Publisher Plugin is not shipped in any of the Red Hat products. Hence, closing as not a bug.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 2jenkins-2-pluginsNot affected
Node HealthCheck Operatorjenkins-2-pluginsNot affected
OpenShift Developer Tools and Servicesjenkins-2-pluginsAffected
Red Hat OpenShift Container Platform 3.11jenkins-2-pluginsAffected
Red Hat OpenShift Container Platform 4jenkins-2-pluginsAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-352
https://bugzilla.redhat.com/show_bug.cgi?id=2215092jenkins-2-plugins: ease-plugin: CSRF vulnerability in Digital.ai App Management Publisher Plugin

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
больше 2 лет назад

A cross-site request forgery (CSRF) vulnerability in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers to connect to an attacker-specified URL, capturing credentials stored in Jenkins.

CVSS3: 4.2
github
больше 2 лет назад

Jenkins Digital.ai App Management Publisher Plugin vulnerable to Cross-Site Request Forgery

4.2 Medium

CVSS3