CVE-2022-36887 – org.jenkins-ci.plugins:jobconfighistory
Package
Manager: maven
Name: org.jenkins-ci.plugins:jobconfighistory
Vulnerable Version: >=0 <1156.v536a_97b_8d649
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00071 pctl0.22257
Details
Jenkins Job Configuration History Plugin does not require POST requests for several HTTP endpoints Jenkins Job Configuration History Plugin 1155.v28a_46a_cc06a_5 and earlier does not require POST requests for several HTTP endpoints, resulting in cross-site request forgery (CSRF) vulnerabilities. These vulnerabilities allow attackers to delete entries from job, agent, and system configuration history, or restore older versions of job, agent, and system configurations. Job Configuration History Plugin 1156.v536a_97b_8d649 requires POST requests for the affected HTTP endpoints.
Metadata
Created: 2022-07-28T00:00:43Z
Modified: 2023-10-27T20:40:53Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-j896-j72w-cr32/GHSA-j896-j72w-cr32.json
CWE IDs: ["CWE-352"]
Alternative ID: GHSA-j896-j72w-cr32
Finding: F007
Auto approve: 1