Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-08388
HistoryJan 16, 2022 - 12:00 a.m.

Jenkins Mailer Plugin Cross-Site Request Forgery Vulnerability

2022-01-1600:00:00
China National Vulnerability Database
www.cnvd.org.cn
10

0.002 Low

EPSS

Percentile

51.4%

Jenkins is a Jenkins open source application. An open source automation server, Jenkins provides hundreds of plug-ins to support building, deploying, and automating any project.A cross-site request forgery vulnerability exists in Jenkins Mailer, which stems from the software’s lack of validation of cross-site request forgery tokens, and could be exploited by an attacker to resolve an attacker-specified hostname.

CPENameOperatorVersion
jenkins mailer pluginlt1.34.2

0.002 Low

EPSS

Percentile

51.4%