Логотип exploitDog
bind:CVE-2022-43408
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-43408

Количество 3

Количество 3

redhat логотип

CVE-2022-43408

больше 3 лет назад

Jenkins Pipeline: Stage View Plugin 2.26 and earlier does not correctly encode the ID of 'input' steps when using it to generate URLs to proceed or abort Pipeline builds, allowing attackers able to configure Pipelines to specify 'input' step IDs resulting in URLs that would bypass the CSRF protection of any target URL in Jenkins.

CVSS3: 5.7
EPSS: Низкий
nvd логотип

CVE-2022-43408

больше 3 лет назад

Jenkins Pipeline: Stage View Plugin 2.26 and earlier does not correctly encode the ID of 'input' steps when using it to generate URLs to proceed or abort Pipeline builds, allowing attackers able to configure Pipelines to specify 'input' step IDs resulting in URLs that would bypass the CSRF protection of any target URL in Jenkins.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-g975-f26h-93g8

больше 3 лет назад

Jenkins Pipeline: Stage View Plugin allows CSRF protection bypass of any target URL in Jenkins

CVSS3: 8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-43408

Jenkins Pipeline: Stage View Plugin 2.26 and earlier does not correctly encode the ID of 'input' steps when using it to generate URLs to proceed or abort Pipeline builds, allowing attackers able to configure Pipelines to specify 'input' step IDs resulting in URLs that would bypass the CSRF protection of any target URL in Jenkins.

CVSS3: 5.7
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-43408

Jenkins Pipeline: Stage View Plugin 2.26 and earlier does not correctly encode the ID of 'input' steps when using it to generate URLs to proceed or abort Pipeline builds, allowing attackers able to configure Pipelines to specify 'input' step IDs resulting in URLs that would bypass the CSRF protection of any target URL in Jenkins.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-g975-f26h-93g8

Jenkins Pipeline: Stage View Plugin allows CSRF protection bypass of any target URL in Jenkins

CVSS3: 8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу