CSRF Vulnerability in Jenkins Job Configuration History Plugin Allows Unauthorized Configuration Modifications

CSRF Vulnerability in Jenkins Job Configuration History Plugin Allows Unauthorized Configuration Modifications

CVE-2022-36887 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

A cross-site request forgery (CSRF) vulnerability in Jenkins Job Configuration History Plugin 1155.v28a_46a_cc06a_5 and earlier allows attackers to delete entries from job, agent, and system configuration history, or restore older versions of job, agent, and system configurations.

Learn more about our Web Application Penetration Testing UK.