CVE-2022-43408 Vulnerability Details

  /     /     /  

CVE-2022-43408 Metadata Quick Info

CVE Published: 19/10/2022 | CVE Updated: 03/08/2024 | CVE Year: 2022
Source: jenkins | Vendor: Jenkins project | Product: Jenkins Pipeline: Stage View Plugin
Status : PUBLISHED

CVE-2022-43408 Description

Jenkins Pipeline: Stage View Plugin 2.26 and earlier does not correctly encode the ID of \'input\' steps when using it to generate URLs to proceed or abort Pipeline builds, allowing attackers able to configure Pipelines to specify \'input\' step IDs resulting in URLs that would bypass the CSRF protection of any target URL in Jenkins.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name:
Source: Jenkins project

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).