CVE-2023-35141

HIGH

Jenkins < 2.400 - Cross-Site Request Forgery via Context Menu URL

Title source: llm
STIX 2.1

Description

In Jenkins 2.399 and earlier, LTS 2.387.3 and earlier, POST requests are sent in order to load the list of context actions. If part of the URL includes insufficiently escaped user-provided values, a victim may be tricked into sending a POST request to an unexpected endpoint by opening a context menu.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/06/14/5

Scores

CVSS v3 8.0
EPSS 0.0016
EPSS Percentile 35.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-352
Status published
Products (3)
jenkins/jenkins < 2.400
jenkins/jenkins < 2.401.1
org.jenkins-ci.main/jenkins-core 0 - 2.400Maven
Published Jun 14, 2023
Tracked Since Feb 18, 2026