A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and earlier, LTS 2.319.1 and earlier allows attackers to trigger build of job without parameters when no security realm is set.
References
Link | Resource |
---|---|
https://www.jenkins.io/security/advisory/2022-01-12/#SECURITY-2558 | Vendor Advisory |
http://www.openwall.com/lists/oss-security/2022/01/12/6 | Mailing List Third Party Advisory |
https://www.oracle.com/security-alerts/cpuapr2022.html | Patch Third Party Advisory |
Information
Published : 2022-01-12 12:15
Updated : 2022-07-29 09:20
NVD link : CVE-2022-20612
Mitre link : CVE-2022-20612
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
oracle
- communications_cloud_native_core_automated_test_suite
jenkins
- jenkins