CSRF Vulnerability in Jenkins Matrix Reloaded Plugin by Jenkins
CVE-2022-34789

6.5MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
30 June 2022

Summary

A cross-site request forgery (CSRF) vulnerability exists in the Jenkins Matrix Reloaded Plugin, specifically in versions 1.1.3 and earlier. This flaw enables attackers to manipulate the Jenkins server's behavior by initiating unauthorized rebuilds of previous matrix builds. By exploiting this vulnerability, an attacker can bypass user authentication procedures, posing a risk to the integrity of build processes and potentially leading to unauthorized access or erroneous build executions.

Affected Version(s)

Jenkins Matrix Reloaded Plugin <= 1.1.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.