CVE-2023-49673
29.11.2023, 14:15
A cross-site request forgery (CSRF) vulnerability in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers to connect to an attacker-specified hostname and port using attacker-specified username and password.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| jenkins | neuvector_vulnerability_scanner | 𝑥 < 2.2 |
| jenkins | jira | 𝑥 < 3.1.2 |
| jenkins | google_compute_engine | 𝑥 < 4.551.0 |
| jenkins | matlab | 𝑥 < 2.11.1 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| jenkins_project | jenkins_neuvector_vulnerability_scanner_plugin | 𝑥 ≤ 1.22 | ADP |
Common Weakness Enumeration