PT-2023-24111 · Jenkins · Jenkins Ldap Plugin+1

Kevin Guerroudj

·

Published

2023-05-16

·

Updated

2025-01-23

·

CVE-2023-32978

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins LDAP Plugin versions 673.v034ec70ec2b b and earlier
Description A cross-site request forgery (CSRF) vulnerability in the Jenkins LDAP Plugin allows attackers to connect to an attacker-specified LDAP server using attacker-specified credentials. This issue arises because the plugin does not require POST requests for a form validation method.
Recommendations For Jenkins LDAP Plugin versions 673.v034ec70ec2b b and earlier, update to a version that requires POST requests for the affected form validation method, such as LDAP Plugin 676.vfa 64cf6b b 002 or later. As a temporary workaround, consider restricting access to the form validation method to minimize the risk of exploitation.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-32978
GHSA-C9QP-6556-JWWP

Affected Products

Jenkins
Jenkins Ldap Plugin