CSRF Vulnerability in Jenkins Build-Publisher Plugin from Jenkins
CVE-2022-41232

8HIGH

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
21 September 2022

Summary

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Jenkins Build-Publisher Plugin, versions prior to 1.22. This flaw allows attackers to manipulate the Jenkins controller by submitting a crafted file name to a specific API endpoint. Consequently, the attacker can replace any config.xml file on the Jenkins controller's file system with an empty file, potentially leading to disruptions in Jenkins operations.

Affected Version(s)

Jenkins Build-Publisher Plugin <= 1.22

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.