CSRF Vulnerability in Jenkins OpenShift Deployer Plugin
CVE-2022-36906
6.5MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 27 July 2022
What is CVE-2022-36906?
A cross-site request forgery vulnerability has been identified in the Jenkins OpenShift Deployer Plugin (v1.2.0 and prior). This flaw enables malicious actors to send unauthorized requests to an attacker-defined endpoint, allowing them to connect using credentials specified by the attacker. This potentially exposes sensitive information and undermines the integrity of the user’s session, making it critical for users to update to the latest version to mitigate risks.
Affected Version(s)
Jenkins OpenShift Deployer Plugin <= 1.2.0