First published: Wed Dec 13 2023(Updated: )
A cross-site request forgery (CSRF) vulnerability in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers to copy jobs.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Deployment Dashboard | <=1.0.10 | |
maven/org.jenkins-ci.plugins:ec2-deployment-dashboard | <=1.0.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-50775 has been classified as a medium severity vulnerability due to its potential impact on sensitive job data.
To fix CVE-2023-50775, upgrade the Jenkins Deployment Dashboard Plugin to version 1.0.11 or later.
CVE-2023-50775 allows attackers to exploit cross-site request forgery to copy Jenkins jobs without user authorization.
CVE-2023-50775 affects Jenkins Deployment Dashboard Plugin versions 1.0.10 and earlier.
CSRF, or Cross-Site Request Forgery, in CVE-2023-50775 is a vulnerability where unauthorized commands can be executed on behalf of an authenticated user.