CVE-2022-20612

Related Vulnerabilities: CVE-2022-20612  

A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and earlier, LTS 2.319.1 and earlier allows attackers to trigger build of job without parameters when no security realm is set.

Description

The MITRE CVE dictionary describes this issue as:

A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and earlier, LTS 2.319.1 and earlier allows attackers to trigger build of job without parameters when no security realm is set.

Additional Information

  • Bugzilla 2044460: CVE-2022-20612 jenkins: no POST request is required for the endpoint handling manual build requests which could result in CSRF
  • CWE-352: Cross-Site Request Forgery (CSRF)
  • FAQ: Frequently asked questions about CVE-2022-20612