CSRF Vulnerability in Jenkins Build-Publisher Plugin from Jenkins
CVE-2022-41232
8HIGH
Key Information:
- Vendor
- Jenkins
- Vendor
- CVE Published:
- 21 September 2022
Summary
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Jenkins Build-Publisher Plugin, versions prior to 1.22. This flaw allows attackers to manipulate the Jenkins controller by submitting a crafted file name to a specific API endpoint. Consequently, the attacker can replace any config.xml file on the Jenkins controller's file system with an empty file, potentially leading to disruptions in Jenkins operations.
Affected Version(s)
Jenkins Build-Publisher Plugin <= 1.22
References
CVSS V3.1
Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved