CSRF Vulnerability in Jenkins OpenShift Deployer Plugin
CVE-2022-36906
6.5MEDIUM
Key Information:
- Vendor
- Jenkins
- Vendor
- CVE Published:
- 27 July 2022
Summary
A cross-site request forgery vulnerability has been identified in the Jenkins OpenShift Deployer Plugin (v1.2.0 and prior). This flaw enables malicious actors to send unauthorized requests to an attacker-defined endpoint, allowing them to connect using credentials specified by the attacker. This potentially exposes sensitive information and undermines the integrity of the user’s session, making it critical for users to update to the latest version to mitigate risks.
Affected Version(s)
Jenkins OpenShift Deployer Plugin <= 1.2.0
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved