Cross-Site Request Forgery in Jenkins Git Plugin
CVE-2022-36882
8.8HIGH
Key Information:
- Vendor
Jenkins
- Status
- Vendor
- CVE Published:
- 27 July 2022
What is CVE-2022-36882?
A cross-site request forgery (CSRF) vulnerability exists in the Jenkins Git Plugin up to version 4.11.3, allowing attackers to exploit built jobs. By leveraging this vulnerability, attackers can initiate builds configured with an unauthorized Git repository and subsequently checkout any specified commit, impacting the integrity and security of the Jenkins environment.
Affected Version(s)
Jenkins Git Plugin <= 4.11.3
Jenkins Git Plugin 4.9.3