PT-2022-20400 · Jenkins · Jenkins Script Security Plugin+1
Published
2022-05-17
·
Updated
2023-12-22
·
CVE-2022-30946
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Script Security Plugin versions 1158.v7c1b 73a 69a 08 and earlier
Description
A cross-site request forgery (CSRF) issue allows attackers to have Jenkins send an HTTP request to an attacker-specified webserver. This occurs because the plugin does not properly validate requests, enabling an attacker to forge requests that Jenkins will execute.
Recommendations
For Jenkins Script Security Plugin versions 1158.v7c1b 73a 69a 08 and earlier, consider disabling the plugin until a patch is available to prevent potential exploitation. Restrict access to the Jenkins interface to minimize the risk of CSRF attacks.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Script Security Plugin