CVE-2023-50775: CSRF
Published Dec 13, 2023
·Updated
A cross-site request forgery (CSRF) vulnerability in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers to copy jobs.
Affected Software
2 affected components
maven/org.jenkins-ci.plugins:ec2-deployment-dashboard<=1.0.10
Jenkins Deployment Dashboard Jenkins<=1.0.10
Event History
Dec 13, 2023
CVE Published
via MITRE·05:30 PM
Data Sourced
via MITRE·05:30 PM
Description
Advisory Published
06:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-50775?
CVE-2023-50775 has been classified as a medium severity vulnerability due to its potential impact on sensitive job data.
2
How do I fix CVE-2023-50775?
To fix CVE-2023-50775, upgrade the Jenkins Deployment Dashboard Plugin to version 1.0.11 or later.
3
What types of attacks are possible with CVE-2023-50775?
CVE-2023-50775 allows attackers to exploit cross-site request forgery to copy Jenkins jobs without user authorization.
4
Which versions of the Jenkins Deployment Dashboard are affected by CVE-2023-50775?
CVE-2023-50775 affects Jenkins Deployment Dashboard Plugin versions 1.0.10 and earlier.
5
What is CSRF in the context of CVE-2023-50775?
CSRF, or Cross-Site Request Forgery, in CVE-2023-50775 is a vulnerability where unauthorized commands can be executed on behalf of an authenticated user.