GHSA-mjmf-7wjw-f5xx, CVE-2023-2631
maven/org.jenkins-ci.plugins/codedx
Cross-Site Request Forgery (CSRF)
A missing permission check in Jenkins Code Dx Plugin 3.1.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.
All versions before 4.0.0
Upgrade to version 4.0.0 or above.
2023-05-18
source |