A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and earlier, LTS 2.319.1 and earlier allows attackers to trigger build of job without parameters when no security realm is set.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0661 | A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and earlier, LTS 2.319.1 and earlier allows attackers to trigger build of job without parameters when no security realm is set. |
Github GHSA |
GHSA-p92q-7fhh-mq35 | Cross-Site Request Forgery in Jenkins |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-03T02:17:53.077Z
Reserved: 2021-10-28T00:00:00
Link: CVE-2022-20612
No data.
Status : Modified
Published: 2022-01-12T20:15:08.653
Modified: 2024-11-21T06:43:09.423
Link: CVE-2022-20612
OpenCVE Enrichment
No data.
EUVD
Github GHSA