cbcvebase.
CVE-2022-43407
published 2022-10-19

CVE-2022-43407: Jenkins Pipeline: Input Step Plugin 451.vf1a_a_4f405289 and earlier does not restrict or sanitize the optionally specified ID of the 'input' step, which is…

high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
Jenkins Pipeline: Input Step Plugin 451.vf1a_a_4f405289 and earlier does not restrict or sanitize the optionally specified ID of the 'input' step, which is used for the URLs that process user interactions for the given 'input' step (proceed or abort) and is not correctly encoded, allowing attackers able to configure Pipelines to have Jenkins build URLs from 'input' step IDs that would bypass the CSRF protection of any target URL in Jenkins when the 'input' step is interacted with.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
jenkinsbmc_ami_devx_code_debug_code_coverage_plugin
jenkinsbmc_ami_devx_total_test_plugin
jenkinsbmc_ami_strobe_measurement_task_plugin
jenkinscode_pipeline_plugin
jenkinscompuware_topaz_utilities_plugin
jenkinscontrast_continuous_application_security_plugin
jenkinscredentials_plugin
jenkinscustom_checkbox_parameter_plugin
jenkinscve-2022-43401_in_script_security_plugin
jenkinsdeclarative_plugin
jenkinsdeprecated_groovy_libraries_plugin
jenkinsfireline_plugin
jenkinsgeneric_webhook_trigger_plugin
jenkinsgitlab_plugin
jenkinsgroovy_libraries_plugin
jenkinsgroovy_plugin
jenkinsinput_step_plugin
jenkinsjob_import_plugin
jenkinsjob_plugin
jenkinskatalon_plugin
jenkinsmercurial_plugin
jenkinsnunit_plugin
jenkinspipeline<= 451.vf1a_a_4f405289
jenkinsrepo_plugin
jenkinss3_explorer_plugin