Cross-Site Request Forgery Vulnerability in Jenkins CONS3RT Plugin
CVE-2022-41253
8.8HIGH
What is CVE-2022-41253?
A cross-site request forgery vulnerability has been identified in the Jenkins CONS3RT Plugin, allowing attackers to connect to a specified HTTP server using credentials that may be exploited through various means. This issue affects versions 1.0.0 and earlier of the CONS3RT Plugin, enabling unauthorized access to stored credentials within Jenkins, which poses a significant risk to the integrity and confidentiality of user data.
Affected Version(s)
Jenkins CONS3RT Plugin <= 1.0.0