Lucene search

K
cveJenkinsCVE-2022-36908
HistoryJul 27, 2022 - 3:15 p.m.

CVE-2022-36908

2022-07-2715:15:10
CWE-352
jenkins
web.nvd.nist.gov
61
5
cve-2022-36908
csrf
jenkins
openshift deployer plugin
security vulnerability
nvd

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

35.1%

A cross-site request forgery (CSRF) vulnerability in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers to check for the existence of an attacker-specified file path on the Jenkins controller file system and to upload a SSH key file from the Jenkins controller file system to an attacker-specified URL.

Affected configurations

Nvd
Node
jenkinsopenshift_deployerRange1.2.0jenkins
VendorProductVersionCPE
jenkinsopenshift_deployer*cpe:2.3:a:jenkins:openshift_deployer:*:*:*:*:*:jenkins:*:*

CNA Affected

[
  {
    "product": "Jenkins OpenShift Deployer Plugin",
    "vendor": "Jenkins project",
    "versions": [
      {
        "lessThanOrEqual": "1.2.0",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThan": "unspecified",
        "status": "unknown",
        "version": "next of 1.2.0",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

35.1%

Related for CVE-2022-36908