CVE-2023-32989

Source
https://cve.org/CVERecord?id=CVE-2023-32989
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-32989.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-32989
Aliases
Published
2023-05-16T16:15:11.310Z
Modified
2025-11-15T06:33:30.132742Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A cross-site request forgery (CSRF) vulnerability in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers to connect to an attacker-specified Azure Cloud server using attacker-specified credentials IDs obtained through another method.

References

Affected packages

Git / github.com/jenkinsci/azure-vm-agents-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/azure-vm-agents-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

759.*
759.v1c1f79435487
760.*
760.ve25700ee68cc
761.*
761.v8d93e0672563
763.*
763.vedbebdfd1222
764.*
764.vf22cf908cb69
765.*
765.vbb9943c5070c
766.*
766.vbdb82c53e70a
768.*
768.vb8b0d31eef4f
774.*
774.v0cee503baa25
775.*
775.v0bbd3d0d016a
777.*
777.v276476e1344c
778.*
778.va3924310a4eb
779.*
779.v5ea1414ec40f
780.*
780.v50d067d02f76
781.*
781.v5877a4d99d28
782.*
782.vb41dc00d85b1
783.*
783.v58077630847d
789.*
789.va0c40e4d0070
793.*
793.vbb935f9be778
794.*
794.v8a62ee91dc70
795.*
795.vd5903dae1139
797.*
797.v31f530348574
799.*
799.va4c741108611
801.*
801.v37f3eab68cf0
802.*
802.vbac7a8a5d5e2
803.*
803.vef83d334600f
804.*
804.ve77d45cc9464
805.*
805.v424cc2981d7a
806.*
806.vae775cde5efa
808.*
808.v9d1999587120
810.*
810.v0a97a847315a
813.*
813.v8ae017133e51
815.*
815.vf2f07da070ee
816.*
816.v27bbb474b2b2
822.*
822.v3a18fc3d2de1
824.*
824.v31b_9c29f67fd
825.*
825.v470cb_9e7361a_
842.*
842.v9fedb_4cc1b_e9
845.*
845.v35ee7c5570db_
846.*
846.v5a_f7e3dce959
851.*
851.v16b_dcb_e85c85
852.*
852.v8d35f0960a_43
azure-vm-agents-0.*
azure-vm-agents-0.4.0
azure-vm-agents-0.4.1
azure-vm-agents-0.4.2
azure-vm-agents-0.4.3
azure-vm-agents-0.4.4
azure-vm-agents-0.4.5
azure-vm-agents-0.4.5.1
azure-vm-agents-0.4.6
azure-vm-agents-0.4.7
azure-vm-agents-0.4.7.1
azure-vm-agents-0.4.8
azure-vm-agents-0.5.0
azure-vm-agents-0.6.0
azure-vm-agents-0.6.1
azure-vm-agents-0.6.2
azure-vm-agents-0.7.0
azure-vm-agents-0.7.1
azure-vm-agents-0.7.2
azure-vm-agents-0.7.2.1
azure-vm-agents-0.7.3
azure-vm-agents-0.7.4
azure-vm-agents-0.7.5
azure-vm-agents-0.8.0
azure-vm-agents-0.8.1
azure-vm-agents-0.9.0
azure-vm-agents-0.9.0-preview
azure-vm-agents-1.*
azure-vm-agents-1.0.0
azure-vm-agents-1.0.1
azure-vm-agents-1.1.0
azure-vm-agents-1.1.1
azure-vm-agents-1.2.0
azure-vm-agents-1.2.1
azure-vm-agents-1.2.2
azure-vm-agents-1.3.0
azure-vm-agents-1.4.0
azure-vm-agents-1.4.1
azure-vm-agents-1.5.0
azure-vm-agents-1.5.1
azure-vm-agents-1.5.2
azure-vm-agents-1.5.3
v0.*
v0.9.1-PREVIEW

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-32989.json"