First published: Thu Mar 23 2023(Updated: )
A cross-site request forgery (CSRF) vulnerability in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.2 and earlier allows attackers to connect to a previously configured Octoperf server using attacker-specified credentials.
Credit: jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Octoperf Load Testing | <=4.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-28674 is classified as a high severity cross-site request forgery vulnerability in Jenkins.
To fix CVE-2023-28674, update the Jenkins OctoPerf Load Testing Plugin to version 4.5.3 or later.
CVE-2023-28674 affects Jenkins OctoPerf Load Testing Plugin versions 4.5.2 and earlier.
CVE-2023-28674 is a cross-site request forgery (CSRF) vulnerability.
An attacker could exploit CVE-2023-28674 to connect to a previously configured OctoPerf server using attacker-specified credentials.