GHSA-rr93-7c6x-8v4v

Suggest an improvement
Source
https://github.com/advisories/GHSA-rr93-7c6x-8v4v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-rr93-7c6x-8v4v/GHSA-rr93-7c6x-8v4v.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-rr93-7c6x-8v4v
Aliases
  • CVE-2023-25767
Published
2023-02-15T15:30:40Z
Modified
2024-02-16T08:21:36.079009Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Cross-Site Request Forgery in Jenkins Azure Credentials Plugin
Details

A cross-site request forgery (CSRF) vulnerability in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers to connect to an attacker-specified web server.

Database specific
{
    "severity": "HIGH",
    "cwe_ids": [
        "CWE-352"
    ],
    "github_reviewed_at": "2023-02-15T18:33:24Z",
    "github_reviewed": true,
    "nvd_published_at": "2023-02-15T14:15:00Z"
}
References

Affected packages

Maven / org.jenkins-ci.plugins:azure-credentials

Package

Name
org.jenkins-ci.plugins:azure-credentials
View open source insights on deps.dev
Purl
pkg:maven/org.jenkins-ci.plugins/azure-credentials

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
254.v64da_8176c83a

Affected versions

1.*
1.0
1.1
1.2
1.3
1.3.1
1.4.0
1.5.0
1.6.0
1.6.1
2.*
2.0.0
2.0.1
2.0.2
3.*
3.0.0
3.0.1
4.*
4.0.0
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
177.*
177.v816b81058012
180.*
180.vd0decee98185
181.*
181.v00b0d97d2686
182.*
182.v3ccd4a755864
189.*
189.v479ef8f0344f
190.*
190.v059127ae17bb
196.*
196.va1e78c9989ea
197.*
197.v2f5ab5b82264
198.*
198.vf9c2fdfde55c
216.*
216.ve0b_4a_485ffc2
242.*
242.vb_f9c4fa_6b_2b_6
252.*
252.vd40e833b_3206
253.*
253.v887e0f9e898b

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-rr93-7c6x-8v4v/GHSA-rr93-7c6x-8v4v.json"
last_known_affected_version_range
"<= 253.v887e0f9e898b"