Lucene search

K
osvGoogleOSV:GHSA-8CRR-XF35-5F5P
HistoryMay 13, 2022 - 1:31 a.m.

Jenkins Job Import Plugin CSRF vulnerability

2022-05-1301:31:34
Google
osv.dev
4

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.6%

A data modification vulnerability exists in Jenkins Job Import Plugin 3.0 and earlier in JobImportAction.java that allows attackers to copy jobs from a preconfigured other Jenkins instance, potentially installing additional plugins necessary to load the imported job’s configuration.

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.6%