Vulnerability Details CVE-2023-35148
A cross-site request forgery (CSRF) vulnerability in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers to connect to an attacker-specified URL, capturing credentials stored in Jenkins.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 29.1%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2023-35148
-
cpe:2.3:a:jenkins:digital.ai_app_management_publisher:-
-
cpe:2.3:a:jenkins:digital.ai_app_management_publisher:1.2.1
-
cpe:2.3:a:jenkins:digital.ai_app_management_publisher:1.2.10
-
cpe:2.3:a:jenkins:digital.ai_app_management_publisher:1.2.11
-
cpe:2.3:a:jenkins:digital.ai_app_management_publisher:1.2.12
-
cpe:2.3:a:jenkins:digital.ai_app_management_publisher:1.2.2
-
cpe:2.3:a:jenkins:digital.ai_app_management_publisher:1.2.3
-
cpe:2.3:a:jenkins:digital.ai_app_management_publisher:1.2.4
-
cpe:2.3:a:jenkins:digital.ai_app_management_publisher:1.2.5
-
cpe:2.3:a:jenkins:digital.ai_app_management_publisher:1.2.6
-
cpe:2.3:a:jenkins:digital.ai_app_management_publisher:1.2.7
-
cpe:2.3:a:jenkins:digital.ai_app_management_publisher:1.2.8
-
cpe:2.3:a:jenkins:digital.ai_app_management_publisher:1.2.9
-
cpe:2.3:a:jenkins:digital.ai_app_management_publisher:2.0
-
cpe:2.3:a:jenkins:digital.ai_app_management_publisher:2.1
-
cpe:2.3:a:jenkins:digital.ai_app_management_publisher:2.2
-
cpe:2.3:a:jenkins:digital.ai_app_management_publisher:2.5
-
cpe:2.3:a:jenkins:digital.ai_app_management_publisher:2.6