Cross-Site Request Forgery in Jenkins Recipe Plugin by Jenkins
CVE-2022-34792
8HIGH
Summary
A cross-site request forgery (CSRF) vulnerability exists in the Jenkins Recipe Plugin version 1.2 and earlier, allowing attackers to construct HTTP requests that can be sent to a user’s session. If exploited, an attacker could direct an authenticated user to interact with an attacker-controlled URL, leading to potential unauthorized actions. This vulnerability highlights the importance of implementing proper security measures to mitigate risks associated with CSRF attacks, especially in integrations involving plugins.
Affected Version(s)
Jenkins Recipe Plugin <= 1.2
References
CVSS V3.1
Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved