CVE-2023-43500: CSRF
A cross-site request forgery (CSRF) vulnerability in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers to connect to an attacker-specified hostname and port using attacker-specified username and password.
Other sources
Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier does not perform a permission check in a connection test HTTP endpoint.
This allows attackers with Overall/Read permission to connect to an attacker-specified hostname and port using attacker-specified username and password.
Additionally, this HTTP endpoint does not require POST requests, resulting in a cross-site request forgery (CSRF) vulnerability.
Build Failure Analyzer Plugin 2.4.2 requires POST requests and Overall/Administer permission for the affected HTTP endpoint.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-43500?
CVE-2023-43500 is a cross-site request forgery (CSRF) vulnerability in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier.
How severe is CVE-2023-43500?
CVE-2023-43500 has a severity score of 8.8, which is considered high.
How does CVE-2023-43500 impact Jenkins Build Failure Analyzer Plugin?
CVE-2023-43500 allows attackers with Overall/Read permission to connect to an attacker-specified hostname and port using attacker-specified username and password.
Which versions of Jenkins Build Failure Analyzer Plugin are affected by CVE-2023-43500?
Jenkins Build Failure Analyzer Plugin versions up to 2.4.2 are affected by CVE-2023-43500.
How can I fix CVE-2023-43500 in Jenkins Build Failure Analyzer Plugin?
To fix CVE-2023-43500, update Jenkins Build Failure Analyzer Plugin to version 2.4.2 or later.