Jenkins Pipeline: Stage View Plugin 2.26 and earlier does not correctly encode the ID of 'input' steps when using it to generate URLs to proceed or abort Pipeline builds, allowing attackers able to configure Pipelines to specify 'input' step IDs resulting in URLs that would bypass the CSRF protection of any target URL in Jenkins.
Metrics
Affected Vendors & Products
References
History
Thu, 08 May 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: jenkins
Published: 2022-10-19T00:00:00.000Z
Updated: 2025-05-08T19:24:47.323Z
Reserved: 2022-10-18T00:00:00.000Z
Link: CVE-2022-43408

Updated: 2024-08-03T13:32:57.398Z

Status : Modified
Published: 2022-10-19T16:15:10.543
Modified: 2025-05-08T20:15:27.163
Link: CVE-2022-43408
