CVE-2022-43408
CVE-2022-43408
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.5EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
19 Oct 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Jenkins Pipeline: Stage View Plugin 2.26 and earlier does not correctly encode the ID of 'input' steps when using it to generate URLs to proceed or abort Pipeline builds, allowing attackers able to configure Pipelines to specify 'input' step IDs resulting in URLs that would bypass the CSRF protection of any target URL in Jenkins.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Affected products
Jenkins project · Jenkins Pipeline: Stage View PluginWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →