Lucene search

K
cveJenkinsCVE-2022-41249
HistorySep 21, 2022 - 4:15 p.m.

CVE-2022-41249

2022-09-2116:15:11
CWE-352
jenkins
web.nvd.nist.gov
54
5
cve-2022-41249
cross-site request forgery
csrf
jenkins
scm httpclient plugin
security vulnerability
nvd

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.6

Confidence

High

EPSS

0.001

Percentile

34.3%

A cross-site request forgery (CSRF) vulnerability in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

Affected configurations

Nvd
Node
jenkinsscm_httpclientRange1.5jenkins
VendorProductVersionCPE
jenkinsscm_httpclient*cpe:2.3:a:jenkins:scm_httpclient:*:*:*:*:*:jenkins:*:*

CNA Affected

[
  {
    "product": "Jenkins SCM HttpClient Plugin",
    "vendor": "Jenkins project",
    "versions": [
      {
        "lessThanOrEqual": "1.5",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThan": "unspecified",
        "status": "unknown",
        "version": "next of 1.5",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.6

Confidence

High

EPSS

0.001

Percentile

34.3%

Related for CVE-2022-41249