CVE-2023-25767: CSRF
Published Feb 15, 2023
·Updated
A cross-site request forgery (CSRF) vulnerability in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers to connect to an attacker-specified web server.
Affected Software
2 affected componentsFixes available
Jenkins Azure Credentials Jenkins<254.v64da_8176c83a
maven/org.jenkins-ci.plugins:azure-credentials<=253.v887e0f9e898b
254.v64da_8176c83a
Event History
Feb 15, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Advisory Published
03:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-25767?
CVE-2023-25767 is classified as a moderate severity cross-site request forgery (CSRF) vulnerability.
2
How do I fix CVE-2023-25767?
To fix CVE-2023-25767, upgrade the Azure Credentials Plugin to version 254.v64da_8176c83a or later.
3
What impact does CVE-2023-25767 have on Jenkins installations?
CVE-2023-25767 allows attackers to potentially connect to an attacker-specified web server, which can lead to unauthorized actions.
4
Which versions of Jenkins Azure Credentials Plugin are affected by CVE-2023-25767?
Versions up to and including 253.v887e0f9e898b of the Azure Credentials Plugin are affected by CVE-2023-25767.
5
Is there a workaround for CVE-2023-25767?
There is no documented workaround for CVE-2023-25767; updating to the latest version is recommended.