PT-2022-26892 · Jenkins · Jenkins Pipeline: Stage View Plugin+1
Daniel Beck
+2
·
Published
2022-10-19
·
Updated
2023-11-01
·
CVE-2022-43408
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Pipeline: Stage View Plugin versions 2.26 and earlier
Description
The issue arises from the incorrect encoding of the ID of
input steps when generating URLs to proceed or abort Pipeline builds, allowing attackers who can configure Pipelines to specify input step IDs. This results in URLs that can bypass the CSRF protection of any target URL in Jenkins.Recommendations
For Jenkins Pipeline: Stage View Plugin versions 2.26 and earlier, update to version 2.27 or later to correctly encode the ID of
input steps and prevent bypassing CSRF protection.
As a temporary workaround, consider restricting access to the input step functionality until the update is applied.Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins
Jenkins Pipeline: Stage View Plugin