Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-43408

Опубликовано: 19 окт. 2022
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Jenkins Pipeline: Stage View Plugin 2.26 and earlier does not correctly encode the ID of 'input' steps when using it to generate URLs to proceed or abort Pipeline builds, allowing attackers able to configure Pipelines to specify 'input' step IDs resulting in URLs that would bypass the CSRF protection of any target URL in Jenkins.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jenkins:pipeline\:stage_view:*:*:*:*:*:jenkins:*:*
Версия до 2.27 (исключая)

EPSS

Процентиль: 1%
0.0001
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-352
CWE-352

Связанные уязвимости

CVSS3: 5.7
redhat
больше 3 лет назад

Jenkins Pipeline: Stage View Plugin 2.26 and earlier does not correctly encode the ID of 'input' steps when using it to generate URLs to proceed or abort Pipeline builds, allowing attackers able to configure Pipelines to specify 'input' step IDs resulting in URLs that would bypass the CSRF protection of any target URL in Jenkins.

CVSS3: 8
github
больше 3 лет назад

Jenkins Pipeline: Stage View Plugin allows CSRF protection bypass of any target URL in Jenkins

EPSS

Процентиль: 1%
0.0001
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-352
CWE-352