CVE-2023-41938: CSRF
Published Sep 6, 2023
·Updated
A cross-site request forgery (CSRF) vulnerability in Jenkins Ivy Plugin 2.5 and earlier allows attackers to delete disabled modules.
Affected Software
2 affected components
maven/org.jenkins-ci.plugins:ivy<=2.5
Jenkins Ivy Jenkins<=2.5
Event History
Sep 6, 2023
CVE Published
12:08 PM
Data Sourced
12:08 PM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·03:30 PM
Frequently Asked Questions
1
What is the vulnerability ID of this cross-site request forgery (CSRF) vulnerability?
The vulnerability ID of this CSRF vulnerability is CVE-2023-41938.
2
What is the severity rating of CVE-2023-41938?
CVE-2023-41938 has a severity rating of 6.5 (medium).
3
Which software versions are affected by CVE-2023-41938?
Versions 2.5 and earlier of Jenkins Ivy Plugin are affected by CVE-2023-41938.
4
What is the impact of CVE-2023-41938?
CVE-2023-41938 allows attackers to delete disabled modules through a CSRF attack.
5
Are there any recommended solutions for CVE-2023-41938?
Yes, the Jenkins team has released a security advisory with recommendations to address the vulnerability. Please refer to the provided references for more information.