Логотип exploitDog
bind:CVE-2023-35141
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-35141

Количество 4

Количество 4

redhat логотип

CVE-2023-35141

больше 2 лет назад

In Jenkins 2.399 and earlier, LTS 2.387.3 and earlier, POST requests are sent in order to load the list of context actions. If part of the URL includes insufficiently escaped user-provided values, a victim may be tricked into sending a POST request to an unexpected endpoint by opening a context menu.

CVSS3: 8
EPSS: Низкий
nvd логотип

CVE-2023-35141

больше 2 лет назад

In Jenkins 2.399 and earlier, LTS 2.387.3 and earlier, POST requests are sent in order to load the list of context actions. If part of the URL includes insufficiently escaped user-provided values, a victim may be tricked into sending a POST request to an unexpected endpoint by opening a context menu.

CVSS3: 8
EPSS: Низкий
debian логотип

CVE-2023-35141

больше 2 лет назад

In Jenkins 2.399 and earlier, LTS 2.387.3 and earlier, POST requests a ...

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-98fp-r22g-wpj7

больше 2 лет назад

Jenkins CSRF protection bypass vulnerability

CVSS3: 8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2023-35141

In Jenkins 2.399 and earlier, LTS 2.387.3 and earlier, POST requests are sent in order to load the list of context actions. If part of the URL includes insufficiently escaped user-provided values, a victim may be tricked into sending a POST request to an unexpected endpoint by opening a context menu.

CVSS3: 8
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-35141

In Jenkins 2.399 and earlier, LTS 2.387.3 and earlier, POST requests are sent in order to load the list of context actions. If part of the URL includes insufficiently escaped user-provided values, a victim may be tricked into sending a POST request to an unexpected endpoint by opening a context menu.

CVSS3: 8
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-35141

In Jenkins 2.399 and earlier, LTS 2.387.3 and earlier, POST requests a ...

CVSS3: 8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-98fp-r22g-wpj7

Jenkins CSRF protection bypass vulnerability

CVSS3: 8
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу