CVE-2023-30529 is a medium-severity vulnerability affecting Jenkins Lucene-Search Plugin versions 387.v938a_ecb_f7fe9 and earlier. It allows unauthenticated attackers to trigger a database reindexing operation due to the lack of POST request enforcement for an HTTP endpoint, potentially causing a denial of service or performance degradation. The vulnerability has a CVSS score of 4.3 (MEDIUM) with low attack complexity, requiring user interaction, and resulting in a low impact on integrity. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 387.v938a_ecb_f7fe9CPE matchmatch criteria | cpe:2.3:a:jenkins:lucene-search:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.