ZeroHour

CVE-2022-20612

CVSS 3.1
4.3 medium
EPSS
2%p77
Published
()
Modified
Description

A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and earlier, LTS 2.319.1 and earlier allows attackers to trigger build of job without parameters when no security realm is set.

Vendors
jenkinsoracle
Products
jenkins, communications cloud native core automated test suite
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.