Cross-Site Request Forgery in Jenkins Delete Log Plugin by Jenkins
CVE-2022-45393
3.5LOW
What is CVE-2022-45393?
A cross-site request forgery (CSRF) vulnerability exists in the Delete Log Plugin for Jenkins, affecting version 1.0 and earlier. This flaw allows attackers to manipulate the plugin, enabling them to delete build logs without proper authorization. If exploited, an attacker could execute unwanted actions on behalf of legitimate users, potentially leading to a loss of crucial build information and hindering development processes.
Affected Version(s)
Jenkins Delete log Plugin <= 1.0