CVE-2023-50778: CSRF
Published Dec 13, 2023
·Updated
A cross-site request forgery (CSRF) vulnerability in Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier allows attackers to connect to an attacker-specified URL using an attacker-specified token.
Affected Software
2 affected components
maven/com.cloudtp.jenkins:paaslane-estimate<=1.0.4
Jenkins Paaslane Estimate Jenkins<=1.0.4
Event History
Dec 13, 2023
CVE Published
via MITRE·05:30 PM
Data Sourced
via MITRE·05:30 PM
Description
Advisory Published
06:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-50778?
CVE-2023-50778 is classified as a high severity vulnerability due to its potential for exploitation through cross-site request forgery.
2
How do I fix CVE-2023-50778?
To remediate CVE-2023-50778, update to Jenkins PaaSLane Estimate Plugin version 1.0.5 or later.
3
What types of systems are affected by CVE-2023-50778?
CVE-2023-50778 affects Jenkins PaaSLane Estimate Plugin version 1.0.4 and earlier.
4
What can an attacker do with CVE-2023-50778?
An attacker can exploit CVE-2023-50778 to send unauthorized requests to an attacker-specified URL using a chosen token.
5
Is CVE-2023-50778 present in any other plugins or software?
CVE-2023-50778 is specifically associated with the Jenkins PaaSLane Estimate Plugin, not other plugins or software.