Description
A cross-site request forgery (CSRF) vulnerability in Jenkins AppSpider Plugin 1.0.15 and earlier allows attackers to connect to an attacker-specified URL and send an HTTP POST request with a JSON payload consisting of attacker-specified credentials.
Remediation
References
https://www.jenkins.io/security/advisory/2023-05-16/#SECURITY-3121
Related Vulnerabilities
CVE-2022-45401 Vulnerability in maven package org.jenkinsci.plugins:associated-files
CVE-2023-31062 Vulnerability in maven package org.apache.inlong:manager-service
CVE-2023-4759 Vulnerability in maven package org.eclipse.jgit:org.eclipse.jgit
CVE-2010-4207 Vulnerability in maven package org.webjars:yui
CVE-2021-21172 Vulnerability in maven package org.webjars.npm:electron