Cross-Site Request Forgery Vulnerability in Jenkins Coverity Plugin
CVE-2022-36920
8.8HIGH
What is CVE-2022-36920?
The vulnerability allows an attacker to exploit the Jenkins Coverity Plugin, specifically versions 1.11.4 and earlier, to initiate unauthorized requests to an attacker-specified URL. By leveraging user credentials stored in Jenkins, an attacker can manipulate the system into connecting to malicious sites, thereby capturing sensitive information such as user credentials. This makes it crucial for users to upgrade to a secure version of the plugin and implement appropriate security measures to prevent exploitation.
Affected Version(s)
Jenkins Coverity Plugin <= 1.11.4