CVE-2022-20613

Related Vulnerabilities: CVE-2022-20613  

A cross-site request forgery (CSRF) vulnerability in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.

Description

The MITRE CVE dictionary describes this issue as:

A cross-site request forgery (CSRF) vulnerability in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.

Additional Information

  • Bugzilla 2044487: CVE-2022-20613 jenkins-2-plugins/mailer: form validation method does not require POST requests which could lead to CSRF
  • CWE-352: Cross-Site Request Forgery (CSRF)
  • FAQ: Frequently asked questions about CVE-2022-20613