Description
A cross-site request forgery (CSRF) vulnerability in Jenkins Job Configuration History Plugin 1155.v28a_46a_cc06a_5 and earlier allows attackers to delete entries from job, agent, and system configuration history, or restore older versions of job, agent, and system configurations.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6361 | A cross-site request forgery (CSRF) vulnerability in Jenkins Job Configuration History Plugin 1155.v28a_46a_cc06a_5 and earlier allows attackers to delete entries from job, agent, and system configuration history, or restore older versions of job, agent, and system configurations. |
Github GHSA |
GHSA-j896-j72w-cr32 | Jenkins Job Configuration History Plugin does not require POST requests for several HTTP endpoints |
References
History
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-03T10:14:29.218Z
Reserved: 2022-07-27T00:00:00.000Z
Link: CVE-2022-36887
No data.
Status : Modified
Published: 2022-07-27T15:15:09.090
Modified: 2024-11-21T07:13:59.637
Link: CVE-2022-36887
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA