Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-43408

Jenkins Pipeline: Stage View Plugin 2.26 and earlier does not correctly encode the ID of 'input' steps when using it to generate URLs to proceed or abort Pipeline builds, allowing attackers able to configure Pipelines to specify 'input' step IDs resulting in URLs that would bypass the CSRF protection of any target URL in Jenkins.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 1.0%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2022-43408
  • Jenkins » Pipeline » Version: stage_view
    cpe:2.3:a:jenkins:pipeline:stage_view


Contact Us

Shodan ® - All rights reserved