CVE-2022-20612

Severity
4.3MEDIUM
EPSS
0.2%
top 57.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 12
Latest updateApr 15

Description

A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and earlier, LTS 2.319.1 and earlier allows attackers to trigger build of job without parameters when no security realm is set.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages4 packages

Patches

🔴Vulnerability Details

3
GHSA
Cross-Site Request Forgery in Jenkins2022-01-21
OSV
Cross-Site Request Forgery in Jenkins2022-01-21
CVEList
CVE-2022-20612: A cross-site request forgery (CSRF) vulnerability in Jenkins 22022-01-12

📋Vendor Advisories

3
Oracle
Oracle Oracle Communications Risk Matrix: Automated Test Suite Framework (Jenkins) — CVE-2022-206122022-04-15
Jenkins
Jenkins Security Advisory 2022-01-122022-01-12
Red Hat
jenkins: no POST request is required for the endpoint handling manual build requests which could result in CSRF2022-01-12