CVE-2022-25205
published 2022-02-15CVE-2022-25205: A cross-site request forgery (CSRF) vulnerability in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers to connect to an attacker-specified database…
high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
A cross-site request forgery (CSRF) vulnerability in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers to connect to an attacker-specified database via JDBC using attacker-specified credentials and to determine if a class is available in the Jenkins instance.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | agent_server_parameter_plugin | — | — |
| jenkins | build_step_plugin | — | — |
| jenkins | checkmarx_plugin | — | — |
| jenkins | chef_sinatra_plugin | — | — |
| jenkins | conjur_secrets_plugin | — | — |
| jenkins | convertigo_mobile_platform_plugin | — | — |
| jenkins | custom_checkbox_parameter_plugin | — | — |
| jenkins | dbcharts | <= 0.5.2 | — |
| jenkins | deprecated_groovy_libraries_plugin | — | — |
| jenkins | doktor_plugin | — | — |
| jenkins | fortify_plugin | — | — |
| jenkins | generic_webhook_trigger_plugin | — | — |
| jenkins | gitlab_authentication_plugin | — | — |
| jenkins | groovy_plugin | — | — |
| jenkins | hashicorp_vault_plugin | — | — |
| jenkins | multibranch_plugin | — | — |
| jenkins | scp_publisher_plugin | — | — |
| jenkins | snow_commander_plugin | — | — |
| jenkins | support_core_plugin | — | — |
| jenkins | swamp_plugin | — | — |
| jenkins | team_views_plugin | — | — |
| jenkins_project | jenkins_dbcharts_plugin | unspecified – 0.5.2 | — |