Lucene search

K
cvelistJenkinsCVELIST:CVE-2023-39153
HistoryJul 26, 2023 - 1:54 p.m.

CVE-2023-39153

2023-07-2613:54:53
jenkins
www.cve.org
cve-2023-39153
cross-site request forgery
jenkins
gitlab authentication plugin
attackers
user tricking

5.9 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

29.0%

A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Authentication Plugin 1.17.1 and earlier allows attackers to trick users into logging in to the attacker’s account.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Jenkins GitLab Authentication Plugin",
    "vendor": "Jenkins Project",
    "versions": [
      {
        "lessThanOrEqual": "1.17.1",
        "status": "affected",
        "version": "0",
        "versionType": "maven"
      }
    ]
  }
]

5.9 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

29.0%

Related for CVELIST:CVE-2023-39153