PT-2022-4029 · Jenkins · Jenkins Job Configuration History Plugin+1
Wadeck Follonier
·
Published
2022-07-27
·
Updated
2023-11-22
·
CVE-2022-36887
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Job Configuration History Plugin versions 1155.v28a 46a cc06a 5 and earlier
Description
The issue is related to a cross-site request forgery (CSRF) vulnerability. This vulnerability can be exploited by a remote attacker to perform a CSRF attack, allowing them to delete entries from job, agent, and system configuration history, or restore older versions of job, agent, and system configurations.
Recommendations
For Jenkins Job Configuration History Plugin versions 1155.v28a 46a cc06a 5 and earlier, update to version 1156.v536a 97b 8d649 or later, which requires POST requests for the affected HTTP endpoints, mitigating the CSRF vulnerability.
At the moment, there is no other information about additional mitigation measures for this vulnerability.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Job Configuration History Plugin