Cross-Site Request Forgery (CSRF) in Jenkins Plug-in for ServiceNow DevOps
Vulnerability Description
A cross-site request forgery vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 that, if exploited successfully, could cause the unwanted exposure of sensitive information. To address this issue, apply the 1.38.1 version of the Jenkins plug-in for ServiceNow DevOps on your Jenkins server. No changes are required on your instances of the Now Platform.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-3414
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Alvaro Muñoz (@pwntester), GitHub Security Lab
More from ServiceNow
View All →Affected Vendor
ServiceNow
View all reports →