CVE Published: 27/07/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: jenkins |
Vendor: Jenkins project |
Product: Jenkins Job Configuration History Plugin Status : PUBLISHED
CVE-2022-36887 Description
A cross-site request forgery (CSRF) vulnerability in Jenkins Job Configuration History Plugin 1155.v28a_46a_cc06a_5 and earlier allows attackers to delete entries from job, agent, and system configuration history, or restore older versions of job, agent, and system configurations.