PT-2022-4021 · Jenkins · Jenkins External Monitor Job Type Plugin+1
Daniel Beck
·
Published
2022-07-27
·
Updated
2023-11-22
·
CVE-2022-36886
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins External Monitor Job Type Plugin versions 191.v363d0d1efdf8 and earlier
Description
A cross-site request forgery (CSRF) vulnerability in the Jenkins External Monitor Job Type Plugin allows attackers to create runs of an external job. This issue arises because the plugin does not require POST requests for a specific HTTP endpoint, making it vulnerable to CSRF attacks. There is no information provided about the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.
Recommendations
For Jenkins External Monitor Job Type Plugin versions 191.v363d0d1efdf8 and earlier, update to version 192.ve979ca 8b 3ccd or later, which requires POST requests for the affected HTTP endpoint, thereby mitigating the CSRF vulnerability.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins External Monitor Job Type Plugin