Bug 2074886 (CVE-2022-29048) - CVE-2022-29048 subversion: CSRF vulnerability in Jenkins Subversion Plugin
Summary: CVE-2022-29048 subversion: CSRF vulnerability in Jenkins Subversion Plugin
Keywords:
Status: NEW
Alias: CVE-2022-29048
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2076257
Blocks: 2074888
TreeView+ depends on / blocked
 
Reported: 2022-04-13 09:30 UTC by Avinash Hanwate
Modified: 2024-05-02 18:49 UTC (History)
9 users (show)

Fixed In Version: subversion plugin 2.15.4
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in the Jenkins subversion plugin. The Jenkins subversion plugin allows attackers to connect to an attacker-specified URL. This flaw allows attackers to trick the user into visiting their website that contains a malicious script, allowing submission to the server on behalf of the user.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Avinash Hanwate 2022-04-13 09:30:07 UTC
A cross-site request forgery (CSRF) vulnerability in Jenkins Subversion Plugin 2.15.3 and earlier allows attackers to connect to an attacker-specified URL.

https://www.jenkins.io/security/advisory/2022-04-12/#SECURITY-2075


Note You need to log in before you can comment on or make changes to this bug.