MEDIUM
jenkins-plugins: cloudbees-folder: CSRF vulnerability in Folders Plugin
Published Aug 16, 2023
4.3
MEDIUMCVSS 3.1
EPSS 0.39%
Description
A cross-site request forgery (CSRF) vulnerability in Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier allows attackers to copy a view inside a folder.
Affected products
-
- Version 0StatusaffectedConstraints<=6.846.v23698686f0f6
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Jenkins Project | Jenkins Folders Plugin | unaffected |
|
No data.
OCP-Tools-4.12-RHEL-8
jenkins-2-plugins-0:4.12.1706515741-1.el8
Fixed · RHSA-2024:0778
OCP-Tools-4.14-RHEL-8
jenkins-2-plugins-0:4.14.1706516441-1.el8
Fixed · RHSA-2024:0777
Red Hat OpenShift Container Platform 3.11
jenkins-2-plugins
Out of support scope
Red Hat OpenShift Container Platform 4
jenkins-2-plugins
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OCP-Tools-4.12-RHEL-8 | jenkins-2-plugins-0:4.12.1706515741-1.el8 | Fixed | RHSA-2024:0778 |
| OCP-Tools-4.14-RHEL-8 | jenkins-2-plugins-0:4.14.1706516441-1.el8 | Fixed | RHSA-2024:0777 |
| Red Hat OpenShift Container Platform 3.11 | jenkins-2-plugins | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 4 | jenkins-2-plugins | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- http://www.openwall.com/lists/oss-security/2023/08/16/3 Mailing List
- https://access.redhat.com/security/cve/CVE-2023-40337 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2232425 Issue Tracking
- https://github.com/advisories/GHSA-22c3-whjv-hrfm Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-40337
- https://www.cve.org/CVERecord?id=CVE-2023-40337
- https://www.jenkins.io/security/advisory/2023-08-16/#SECURITY-3105 vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2023/08/16/3 | Mailing List | |
| https://access.redhat.com/security/cve/CVE-2023-40337 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2232425 | Issue Tracking | |
| https://github.com/advisories/GHSA-22c3-whjv-hrfm | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-40337 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-40337 | ||
| https://www.jenkins.io/security/advisory/2023-08-16/#SECURITY-3105 | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner jenkins
Published Aug 16, 2023
Updated Oct 8, 2024
Reserved Aug 14, 2023
Link CVE-2023-40337
CISA Vulnrichment
GHSA-22C3-WHJV-HRFM Updated Oct 8, 2024