CVE-2022-25205: CSRF
Published Feb 15, 2022
·Updated
A cross-site request forgery (CSRF) vulnerability in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers to connect to an attacker-specified database via JDBC using attacker-specified credentials and to determine if a class is available in the Jenkins instance.
Affected Software
2 affected components
maven/org.jenkins-ci.plugins:dbCharts<=0.5.2
Jenkins Dbcharts Jenkins<=0.5.2
Remediation
Event History
Feb 15, 2022
CVE Published
via MITRE·04:11 PM
Data Sourced
via MITRE·04:11 PM
Description
Feb 16, 2022
Advisory Published
12:01 AM
Frequently Asked Questions
1
What is the severity of CVE-2022-25205?
CVE-2022-25205 has a medium severity rating, indicating a moderate risk of exploitation.
2
How do I fix CVE-2022-25205?
To mitigate CVE-2022-25205, upgrade the Jenkins dbCharts Plugin to version 0.5.3 or later.
3
What are the primary risks associated with CVE-2022-25205?
CVE-2022-25205 potentially allows attackers to connect to a database with attacker-specified credentials using CSRF exploits.
4
Which versions of Jenkins dbCharts Plugin are affected by CVE-2022-25205?
CVE-2022-25205 affects Jenkins dbCharts Plugin versions 0.5.2 and earlier.
5
Can CVE-2022-25205 lead to unauthorized data access?
Yes, CVE-2022-25205 can enable unauthorized database access which may expose sensitive information.