Cross-Site Request Forgery Vulnerability in Jenkins Openstack Heat Plugin
CVE-2022-36911
6.5MEDIUM
Summary
A cross-site request forgery (CSRF) vulnerability exists in Jenkins Openstack Heat Plugin 1.5 and earlier, enabling attackers to initiate unauthorized actions by sending requests from a user's browser to an attacker-specified URL. This can lead to potential unauthorized access and manipulation of data.
Affected Version(s)
Jenkins Openstack Heat Plugin <= 1.5
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved