CSRF Vulnerability in Jenkins Build-Publisher Plugin from Jenkins
CVE-2022-41232
8HIGH
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 21 September 2022
What is CVE-2022-41232?
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Jenkins Build-Publisher Plugin, versions prior to 1.22. This flaw allows attackers to manipulate the Jenkins controller by submitting a crafted file name to a specific API endpoint. Consequently, the attacker can replace any config.xml file on the Jenkins controller's file system with an empty file, potentially leading to disruptions in Jenkins operations.
Affected Version(s)
Jenkins Build-Publisher Plugin <= 1.22