CVE-2022-34815

MEDIUM4.3EPSS 0.08%

Cross-Site Request Forgery in Jenkins Request Rename Or Delete Plugin

Published: 7/1/2022Modified: 11/8/2023

Description

A cross-site request forgery (CSRF) vulnerability in Jenkins Request Rename Or Delete Plugin 1.1.0 and earlier allows attackers to accept pending requests, thereby renaming or deleting jobs.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

References (3)