Lucene search

K
cvelistJenkinsCVELIST:CVE-2023-41946
HistorySep 06, 2023 - 12:09 p.m.

CVE-2023-41946

2023-09-0612:09:02
jenkins
www.cve.org
1
cve-2023-41946
cross-site request forgery
jenkins
frugal testing plugin
attacker-specified credentials
test ids
security vulnerability

4.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.3%

A cross-site request forgery (CSRF) vulnerability in Jenkins Frugal Testing Plugin 1.1 and earlier allows attackers to connect to Frugal Testing using attacker-specified credentials, and to retrieve test IDs and names from Frugal Testing, if a valid credential corresponds to the attacker-specified username.

CNA Affected

[
  {
    "defaultStatus": "unknown",
    "product": "Jenkins Frugal Testing Plugin",
    "vendor": "Jenkins Project",
    "versions": [
      {
        "lessThanOrEqual": "1.1",
        "status": "affected",
        "version": "0",
        "versionType": "maven"
      }
    ]
  }
]

4.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.3%

Related for CVELIST:CVE-2023-41946