cbcvebase.
CVE-2022-30969
published 2022-05-17

CVE-2022-30969: A cross-site request forgery (CSRF) vulnerability in Jenkins Autocomplete Parameter Plugin 1.1 and earlier allows attackers to execute arbitrary code without…

PriorityP337high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.84%
53.6th percentile
A cross-site request forgery (CSRF) vulnerability in Jenkins Autocomplete Parameter Plugin 1.1 and earlier allows attackers to execute arbitrary code without sandbox protection if the victim is an administrator.

Affected

22 ranges
VendorProductVersion rangeFixed in
jenkinsapplication_detector_plugin
jenkinsautocomplete_parameter<= 1.1
jenkinsautocomplete_parameter_plugin
jenkinsblue_ocean_plugin
jenkinsgit_plugin
jenkinsgitlab_plugin
jenkinsglobal_variable_string_parameter_plugin
jenkinsgroovy_plugin
jenkinshttp_requests_in_script_security_plugin
jenkinsjdk_parameter_plugin
jenkinsjenkins_core
jenkinsmercurial_plugin
jenkinsmultiselect_parameter_plugin
jenkinsrandom_string_parameter_plugin
jenkinsrepo_plugin
jenkinsrundeck_plugin
jenkinsscript_security_plugin
jenkinsselection_tasks_plugin
jenkinsssh_plugin
jenkinsstorable_configs_plugin
jenkinswhile_credentials_plugin
jenkins_projectjenkins_autocomplete_parameter_pluginunspecified – 1.1

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.