Cross-Site Request Forgery Vulnerability in Jenkins SCP Publisher Plugin
CVE-2022-25198
8.8HIGH
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 15 February 2022
What is CVE-2022-25198?
The SCP Publisher Plugin for Jenkins has a cross-site request forgery vulnerability that enables attackers to force the plugin to connect to an SSH server of their choice using credentials provided by the attacker. This flaw poses significant risks as it allows unauthorized access and actions on behalf of authenticated users, potentially leading to data breaches or compromise of the Jenkins environment.
Affected Version(s)
Jenkins SCP publisher Plugin <= 1.8