PT-2022-27501 · Jenkins · Jenkins Cluster Statistics Plugin+1
Cc Bomber
·
Published
2022-11-15
·
Updated
2023-11-01
·
CVE-2022-45399
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Cluster Statistics Plugin versions 0.4.6 and earlier
Description
A missing permission check in the Jenkins Cluster Statistics Plugin allows attackers to delete recorded Jenkins Cluster Statistics. This issue is related to an HTTP endpoint that does not require POST requests, resulting in a cross-site request forgery (CSRF) vulnerability. Attackers with Overall/Read permission can exploit this issue.
Recommendations
For Jenkins Cluster Statistics Plugin versions 0.4.6 and earlier, as a temporary workaround, consider restricting access to the affected HTTP endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Cluster Statistics Plugin