ZeroHour

CVE-2023-39153

CVSS 3.1
5.4 medium
EPSS
<1%p51
Published
()
Modified
Description

A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Authentication Plugin 1.17.1 and earlier allows attackers to trick users into logging in to the attacker's account.

Vendors
jenkins
Products
gitlab authentication
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.