PT-2022-15858 · Jenkins · Jenkins Batch Task Plugin+1

Tomasz Szuba

·

Published

2022-01-12

·

Updated

2023-11-30

·

CVE-2022-23115

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Jenkins batch task Plugin versions 1.19 and earlier
Description The issue allows attackers with Overall/Read access to perform certain actions due to cross-site request forgery (CSRF) vulnerabilities. These actions include retrieving logs, building, or deleting a batch task.
Recommendations For Jenkins batch task Plugin versions 1.19 and earlier, consider restricting access to the plugin to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit the Overall/Read access to authorized personnel only.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2022-23115
GHSA-MH8G-8JWP-Q6XW

Affected Products

Jenkins
Jenkins Batch Task Plugin