CVE-2023-30529: Jenkins Lucene-Search

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Jenkins Lucene-Search Plugin 387.v938a_ecb_f7fe9 and earlier does not require POST requests for an HTTP endpoint, allowing attackers to reindex the database.

Affected products

  • Jenkins Lucene-Search: up to and including 387.v938a_ecb_f7fe9

Published 2023-04-12. Last modified 2026-06-17.