PT-2023-3358 · Jenkins · Jenkins Reverse Proxy Auth Plugin+1

Kevin Guerroudj

·

Published

2023-05-16

·

Updated

2023-05-25

·

CVE-2023-32987

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Jenkins Reverse Proxy Auth Plugin versions 1.7.4 and earlier
Description The issue is related to a cross-site request forgery (CSRF) vulnerability. This vulnerability allows attackers to connect to an attacker-specified LDAP server using attacker-specified credentials. The exploitation of this issue may enable an attacker to perform a CSRF attack.
Recommendations For Jenkins Reverse Proxy Auth Plugin versions 1.7.4 and earlier, update to version 1.7.5 or later, which requires POST requests for the affected form validation method, thus mitigating the CSRF vulnerability.

Fix

CSRF

Weakness Enumeration

Related Identifiers

BDU:2023-03514
CVE-2023-32987
GHSA-PMMR-R9V2-59P8

Affected Products

Jenkins
Jenkins Reverse Proxy Auth Plugin