CVE-2022-29048
published 2022-04-12CVE-2022-29048: A cross-site request forgery (CSRF) vulnerability in Jenkins Subversion Plugin 2.15.3 and earlier allows attackers to connect to an attacker-specified URL.
PriorityP420medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
1.80%
76.0th percentile
A cross-site request forgery (CSRF) vulnerability in Jenkins Subversion Plugin 2.15.3 and earlier allows attackers to connect to an attacker-specified URL.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | >= 12.0 < 12.5 | 12.5 |
| apple | macos_monterey | — | — |
| jenkins | build_step_plugin | — | — |
| jenkins | coordinator_plugin | — | — |
| jenkins | credentials_plugin | — | — |
| jenkins | cvs_plugin | — | — |
| jenkins | deprecated_groovy_libraries_plugin | — | — |
| jenkins | extended_choice_parameter_plugin | — | — |
| jenkins | gerrit_trigger_plugin | — | — |
| jenkins | git_parameter_plugin | — | — |
| jenkins | google_compute_engine_plugin | — | — |
| jenkins | input_step_plugin | — | — |
| jenkins | jira_plugin | — | — |
| jenkins | job_dsl_plugin | — | — |
| jenkins | job_generator_plugin | — | — |
| jenkins | mask_passwords_plugin | — | — |
| jenkins | maven_release_plugin | — | — |
| jenkins | node_and_label_parameter_plugin | — | — |
| jenkins | promotion_names_in_promoted_builds_plugin | — | — |
| jenkins | publish_over_ftp_plugin | — | — |
| jenkins | rebuilder_plugin | — | — |
| jenkins | release_plugin | — | — |
| jenkins | show_build_parameters_plugin | — | — |
| jenkins | subversion | <= 2.15.3 | — |
| jenkins | subversion_plugin | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2022-29048: macOS Monterey 12.5
vendor_apple·2022-07-20·CVSS 4.3
CVE-2022-29048 [MEDIUM] CVE-2022-29048: macOS Monterey 12.5
Apple Security Update: About the security content of macOS Monterey 12.5
Product: macOS Monterey
Version: 12.5
CVE: CVE-2022-29048
Component: Spotlight
Impact: An app may be able to gain root privileges
Description: This issue was addressed with improved checks.
Jenkins
Jenkins Security Advisory 2022-04-12
vendor_jenkins·2022-04-12·CVSS 5.4
CVE-2017-2601 [MEDIUM] Jenkins Security Advisory 2022-04-12
Title: Jenkins Security Advisory 2022-04-12
Jenkins Security Advisory 2022-04-12
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Credentials
Plugin
CVS
Plugin
Extended Choice Parameter
Plugin
Gerrit Trigger
Plugin
Git Parameter
Plugin
Google Compute Engine
Plugin
Jira
Plugin
Job Generator
Red Hat
subversion: CSRF vulnerability in Jenkins Subversion Plugin
vendor_redhat·2022-04-12·CVSS 4.3
CVE-2022-29048 [MEDIUM] CWE-352 subversion: CSRF vulnerability in Jenkins Subversion Plugin
subversion: CSRF vulnerability in Jenkins Subversion Plugin
A cross-site request forgery (CSRF) vulnerability in Jenkins Subversion Plugin 2.15.3 and earlier allows attackers to connect to an attacker-specified URL.
A flaw was found in the Jenkins subversion plugin. The Jenkins subversion plugin allows attackers to connect to an attacker-specified URL. This flaw allows attackers to trick the user into visiting their website that contains a malicious script, allowing submission to the server on behalf of the user.
Package: jenkins-2-plugins (Red Hat OpenShift Container Platform 3.11) - Out of support scope
Package: jenkins-2-plugins (Red Hat OpenShift Container Platform 4) - Affected
OSV
CSRF vulnerability in Jenkins Subversion Plugin
osv·2022-04-13
CVE-2022-29048 [MEDIUM] CSRF vulnerability in Jenkins Subversion Plugin
CSRF vulnerability in Jenkins Subversion Plugin
Subversion Plugin 2.15.3 and earlier does not require POST requests for several form validation methods, resulting in cross-site request forgery (CSRF) vulnerabilities.
These vulnerabilities allow attackers to connect to an attacker-specified URL.
GHSA
CSRF vulnerability in Jenkins Subversion Plugin
ghsa·2022-04-13
CVE-2022-29048 [MEDIUM] CWE-352 CSRF vulnerability in Jenkins Subversion Plugin
CSRF vulnerability in Jenkins Subversion Plugin
Subversion Plugin 2.15.3 and earlier does not require POST requests for several form validation methods, resulting in cross-site request forgery (CSRF) vulnerabilities.
These vulnerabilities allow attackers to connect to an attacker-specified URL.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-04-12
Published