PT-2023-24111 · Jenkins · Jenkins Ldap Plugin+1
Kevin Guerroudj
·
Published
2023-05-16
·
Updated
2025-01-23
·
CVE-2023-32978
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins LDAP Plugin versions 673.v034ec70ec2b b and earlier
Description
A cross-site request forgery (CSRF) vulnerability in the Jenkins LDAP Plugin allows attackers to connect to an attacker-specified LDAP server using attacker-specified credentials. This issue arises because the plugin does not require POST requests for a form validation method.
Recommendations
For Jenkins LDAP Plugin versions 673.v034ec70ec2b b and earlier, update to a version that requires POST requests for the affected form validation method, such as LDAP Plugin 676.vfa 64cf6b b 002 or later. As a temporary workaround, consider restricting access to the form validation method to minimize the risk of exploitation.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Ldap Plugin