PT-2022-22367 · Jenkins · Jenkins Request Rename/Delete Plugin+1
Kevin Guerroudj
·
Published
2022-06-30
·
Updated
2023-11-22
·
CVE-2022-34815
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Request Rename Or Delete Plugin version 1.1.0 and earlier
Description
A cross-site request forgery issue allows attackers to accept pending requests, which can lead to renaming or deleting jobs.
Recommendations
For Jenkins Request Rename Or Delete Plugin version 1.1.0 and earlier, consider disabling the plugin until a patch is available to prevent exploitation.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Request Rename/Delete Plugin