Description
A cross-site request forgery (CSRF) vulnerability in Jenkins HTMLResource Plugin 1.02 and earlier allows attackers to delete arbitrary files on the Jenkins controller file system.
Remediation
References
https://www.jenkins.io/security/advisory/2023-12-13/#SECURITY-3183
http://www.openwall.com/lists/oss-security/2023/12/13/4
Related Vulnerabilities
CVE-2017-12629 Vulnerability in maven package org.apache.solr:solr-core
CVE-2018-1000173 Vulnerability in maven package org.jenkins-ci.plugins:google-login
CVE-2023-51656 Vulnerability in maven package org.apache.iotdb:iotdb-server
CVE-2021-1626 Vulnerability in maven package org.mule.runtime:mule-core
CVE-2019-3773 Vulnerability in maven package org.springframework.ws:spring-xml