CVE-2023-41946: Jenkins Frugal Testing

Low severity, CVSS 3.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A cross-site request forgery (CSRF) vulnerability in Jenkins Frugal Testing Plugin 1.1 and earlier allows attackers to connect to Frugal Testing using attacker-specified credentials, and to retrieve test IDs and names from Frugal Testing, if a valid credential corresponds to the attacker-specified username.

Affected products

  • Jenkins Frugal Testing: up to and including 1.1

Published 2023-09-06. Last modified 2026-06-17.