PT-2022-22340 · Jenkins · Jenkins Matrix Reloaded Plugin+1
Github.Com/Jetersen
·
Published
2022-06-30
·
Updated
2023-11-03
·
CVE-2022-34789
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Matrix Reloaded Plugin versions 1.1.3 and earlier
Description
A cross-site request forgery (CSRF) vulnerability allows attackers to rebuild previous matrix builds. This issue arises because the plugin does not require POST requests for an HTTP endpoint, making it vulnerable to CSRF attacks.
Recommendations
For Jenkins Matrix Reloaded Plugin versions 1.1.3 and earlier, consider disabling the rebuild functionality for matrix builds until a patch is available. Restrict access to the affected HTTP endpoint to minimize the risk of exploitation. As a temporary workaround, ensure that all rebuild requests are validated to prevent unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Matrix Reloaded Plugin