Description
A cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On(SSO) Plugin 2.0.0 and earlier allows attackers to send an HTTP POST request with JSON body containing attacker-specified content, to miniOrange's API for sending emails.
Remediation
References
https://www.jenkins.io/security/advisory/2023-05-16/#SECURITY-2994
Related Vulnerabilities
CVE-2023-50730 Vulnerability in maven package edu.gemini:gsp-graphql-core_native0.4_2.13
CVE-2021-21612 Vulnerability in maven package de.tracetronic.jenkins.plugins:ecutest
CVE-2022-0225 Vulnerability in maven package org.keycloak:keycloak-core
CVE-2022-42127 Vulnerability in maven package com.liferay:com.liferay.friendly.url.web