Description
A cross-site request forgery (CSRF) vulnerability in Jenkins Convert To Pipeline Plugin 1.0 and earlier allows attackers to create a Pipeline based on a Freestyle project, potentially leading to remote code execution (RCE).
Remediation
References
https://www.jenkins.io/security/advisory/2023-03-21/#SECURITY-2963
Related Vulnerabilities
CVE-2022-39248 Vulnerability in maven package org.matrix.android:matrix-android-sdk2
CVE-2017-5929 Vulnerability in maven package ch.qos.logback:logback-classic
CVE-2016-8751 Vulnerability in maven package org.apache.ranger:ranger
CVE-2016-3089 Vulnerability in maven package org.apache.openmeetings:openmeetings-web
CVE-2018-17194 Vulnerability in maven package org.apache.nif:nifi-framework-cluster