Description
A cross-site request forgery (CSRF) vulnerability in Jenkins Gerrit Trigger Plugin 2.38.0 and earlier allows attackers to rebuild previous builds triggered by Gerrit.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0422 | A cross-site request forgery (CSRF) vulnerability in Jenkins Gerrit Trigger Plugin 2.38.0 and earlier allows attackers to rebuild previous builds triggered by Gerrit. |
Github GHSA |
GHSA-95jq-24cr-pgrq | Cross-site request forgery in Jenkins Gerrit Trigger Plugin |
References
History
Wed, 02 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-04-02T14:27:49.805Z
Reserved: 2023-01-23T00:00:00.000Z
Link: CVE-2023-24423
Updated: 2024-08-02T10:56:03.773Z
Status : Modified
Published: 2023-01-26T21:18:16.707
Modified: 2025-04-02T15:15:54.433
Link: CVE-2023-24423
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-352
Cross-Site Request Forgery (CSRF)
EUVD
Github GHSA