Is org.jenkins-ci.plugins:reverse-proxy-auth-pluginsafe?
2 known vulnerabilities, worst severity MODERATE.
cvss
8.8
how bad it is if exploited, out of 10
epss
0.40%
chance of exploitation in the next 30 days
xyz score
not scored
CyberXYZ composite, out of 10
fig. 01 — GHSA-pmmr-r9v2-59p8, the advisory selected below
// advisories
GHSA-pmmr-r9v2-59p8
MODERATECVE-2023-32987
Jenkins Reverse Proxy Auth Plugin 1.7.4 and earlier does not require POST requests for a form validation method, resulting in a cross-site request forgery (CSRF) vulnerability.