Related Vulnerabilities: CVE-2022-36882  

A cross-site request forgery (CSRF) vulnerability in Jenkins Git Plugin 4.11.3 and earlier allows attackers to trigger builds of jobs configured to use an attacker-specified Git repository and to cause them to check out an attacker-specified commit.

Description

The MITRE CVE dictionary describes this issue as:

A cross-site request forgery (CSRF) vulnerability in Jenkins Git Plugin 4.11.3 and earlier allows attackers to trigger builds of jobs configured to use an attacker-specified Git repository and to cause them to check out an attacker-specified commit.

Additional Information

  • Bugzilla 2116840: CVE-2022-36882 jenkins-plugin: Cross-site Request Forgery (CSRF) in org.jenkins-ci.plugins:git
  • CWE-352: Cross-Site Request Forgery (CSRF)
  • FAQ: Frequently asked questions about CVE-2022-36882