CVE-2024-3825
Severity CVSS v4.0:
Pending analysis
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
17/04/2024
Last modified:
15/04/2026
Description
Versions of the BlazeMeter Jenkins plugin prior to 4.22 contain a flaw which results in credential enumeration<br />
Impact
Base Score 3.x
4.30
Severity 3.x
MEDIUM
References to Advisories, Solutions, and Tools
- https://github.com/Blazemeter/blazemeter-jenkins-plugin/commit/11ec94f68136a0612ae1b37b5370053132cb2528
- https://portal.perforce.com/s/detail/a91PA000001STsvYAG
- https://github.com/Blazemeter/blazemeter-jenkins-plugin/commit/11ec94f68136a0612ae1b37b5370053132cb2528
- https://portal.perforce.com/s/detail/a91PA000001STsvYAG



