CVE-2023-41942: CSRF
A cross-site request forgery (CSRF) vulnerability in Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier allows attackers to clear the SQS queue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-41942?
The severity of CVE-2023-41942 is medium with a score of 4.3.
How does the CSRF vulnerability in Jenkins AWS CodeCommit Trigger Plugin affect me?
The CSRF vulnerability in Jenkins AWS CodeCommit Trigger Plugin allows attackers to clear the SQS queue.
What software versions are affected by CVE-2023-41942?
CVE-2023-41942 affects Jenkins AWS CodeCommit Trigger Plugin versions up to and including 3.0.12.
Is there a fix for CVE-2023-41942?
Yes, upgrading to a version higher than 3.0.12 of Jenkins AWS CodeCommit Trigger Plugin will fix the vulnerability.
Where can I find more information about CVE-2023-41942?
You can find more information about CVE-2023-41942 in the following references: [Reference 1](http://www.openwall.com/lists/oss-security/2023/09/06/9), [Reference 2](https://www.jenkins.io/security/advisory/2023-09-06/#SECURITY-3101%20(2)).