PT-2022-27501 · Jenkins · Jenkins Cluster Statistics Plugin+1

Cc Bomber

·

Published

2022-11-15

·

Updated

2023-11-01

·

CVE-2022-45399

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Cluster Statistics Plugin versions 0.4.6 and earlier
Description A missing permission check in the Jenkins Cluster Statistics Plugin allows attackers to delete recorded Jenkins Cluster Statistics. This issue is related to an HTTP endpoint that does not require POST requests, resulting in a cross-site request forgery (CSRF) vulnerability. Attackers with Overall/Read permission can exploit this issue.
Recommendations For Jenkins Cluster Statistics Plugin versions 0.4.6 and earlier, as a temporary workaround, consider restricting access to the affected HTTP endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-45399
GHSA-W8WG-62WF-62GM

Affected Products

Jenkins
Jenkins Cluster Statistics Plugin