{ "id": "CVE-2023-37964", "sourceIdentifier": "jenkinsci-cert@googlegroups.com", "published": "2023-07-12T16:15:14.143", "lastModified": "2023-07-13T23:15:12.320", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "A cross-site request forgery (CSRF) vulnerability in Jenkins ElasticBox CI Plugin 5.0.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins." } ], "metrics": {}, "references": [ { "url": "http://www.openwall.com/lists/oss-security/2023/07/12/2", "source": "jenkinsci-cert@googlegroups.com" }, { "url": "https://www.jenkins.io/security/advisory/2023-07-12/#SECURITY-3131", "source": "jenkinsci-cert@googlegroups.com" } ] }