PT-2022-4021 · Jenkins · Jenkins External Monitor Job Type Plugin+1

Daniel Beck

·

Published

2022-07-27

·

Updated

2023-11-22

·

CVE-2022-36886

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Jenkins External Monitor Job Type Plugin versions 191.v363d0d1efdf8 and earlier
Description A cross-site request forgery (CSRF) vulnerability in the Jenkins External Monitor Job Type Plugin allows attackers to create runs of an external job. This issue arises because the plugin does not require POST requests for a specific HTTP endpoint, making it vulnerable to CSRF attacks. There is no information provided about the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.
Recommendations For Jenkins External Monitor Job Type Plugin versions 191.v363d0d1efdf8 and earlier, update to version 192.ve979ca 8b 3ccd or later, which requires POST requests for the affected HTTP endpoint, thereby mitigating the CSRF vulnerability.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04854
CVE-2022-36886
GHSA-6X63-HRXG-2HJX

Affected Products

Jenkins
Jenkins External Monitor Job Type Plugin