CSRF Vulnerability in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.0 and Earlier Allows Unauthorized Credential Capture

CSRF Vulnerability in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.0 and Earlier Allows Unauthorized Credential Capture

CVE-2023-28671 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

A cross-site request forgery (CSRF) vulnerability in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

Learn more about our Web Application Penetration Testing UK.