CVE-2023-25767 is a high-severity Cross-Site Request Forgery (CSRF) vulnerability affecting Jenkins Azure Credentials Plugin versions 253.v887e0f9e898b and earlier. This flaw allows an unauthenticated attacker to trick a user into connecting to an attacker-controlled web server, potentially leading to high impact on confidentiality, integrity, and availability. While the CVSS score is 8.8, there is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 254.v64da_8176c83aCPE matchmatch criteria | cpe:2.3:a:jenkins:azure_credentials:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.