PT-2022-20425 · Jenkins · Jenkins Autocomplete Parameter Plugin+1

Justin Philip

+3

·

Published

2022-05-17

·

Updated

2023-11-03

·

CVE-2022-30969

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins Autocomplete Parameter Plugin versions 1.1 and earlier
Description A cross-site request forgery (CSRF) issue allows attackers to execute arbitrary code without sandbox protection if the victim is an administrator.
Recommendations For Jenkins Autocomplete Parameter Plugin versions 1.1 and earlier, update to a version that fixes this issue to prevent arbitrary code execution. As a temporary workaround, consider restricting access to administrative functions to minimize the risk of exploitation.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2022-30969
GHSA-7C3V-2JJV-HQ3C

Affected Products

Jenkins
Jenkins Autocomplete Parameter Plugin