First published: Wed Aug 16 2023(Updated: )
A cross-site request forgery (CSRF) vulnerability in Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier allows attackers to copy a view inside a folder.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Folders | <=6.846.v23698686f0f6 | |
maven/org.jenkins-ci.plugins:cloudbees-folder | <6.848.ve3b | 6.848.ve3b |
redhat/Folders Plugin | <6.848. | 6.848. |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-40337 is a cross-site request forgery (CSRF) vulnerability in Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier, which allows attackers to copy a view inside a folder.
CVE-2023-40337 has a severity value of 4.3 which is considered medium.
Jenkins Folders Plugin versions 6.846.v23698686f0f6 and earlier are affected by CVE-2023-40337.
To fix CVE-2023-40337, update Jenkins Folders Plugin to version 6.848.ve3b_fd7839a_81 or later.
You can find more information about CVE-2023-40337 in the NVD (National Vulnerability Database) and Jenkins Security Advisory. Links: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-40337), [Jenkins Security Advisory](https://www.jenkins.io/security/advisory/2023-08-16/#SECURITY-3105)