CVE-2023-30529
Severity CVSS v4.0:
Pending analysis
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
12/04/2023
Last modified:
07/02/2025
Description
Jenkins Lucene-Search Plugin 387.v938a_ecb_f7fe9 and earlier does not require POST requests for an HTTP endpoint, allowing attackers to reindex the database.
Impact
Base Score 3.x
4.30
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:jenkins:lucene-search:*:*:*:*:*:jenkins:*:* | 387.v938a_ecb_f7fe9 (including) |
To consult the complete list of CPE names with products and versions, see this page