CVE-2022-43408

Source
https://cve.org/CVERecord?id=CVE-2022-43408
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-43408.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-43408
Aliases
Downstream
Published
2022-10-19T16:15:10.543Z
Modified
2026-03-14T14:47:54.869859Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

Jenkins Pipeline: Stage View Plugin 2.26 and earlier does not correctly encode the ID of 'input' steps when using it to generate URLs to proceed or abort Pipeline builds, allowing attackers able to configure Pipelines to specify 'input' step IDs resulting in URLs that would bypass the CSRF protection of any target URL in Jenkins.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "2.27"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-43408.json"