CVE-2022-25212: CSRF
Published Feb 15, 2022
·Updated
A cross-site request forgery (CSRF) vulnerability in Jenkins SWAMP Plugin 1.2.6 and earlier allows attackers to connect to an attacker-specified web server using attacker-specified credentials.
Affected Software
1 affected component
Jenkins Swamp Jenkins<=1.2.6
Event History
Feb 15, 2022
CVE Published
via MITRE·04:11 PM
Data Sourced
via MITRE·04:11 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-25212?
CVE-2022-25212 has been classified with a medium severity score due to its potential impact on user data and security.
2
How do I fix CVE-2022-25212?
To fix CVE-2022-25212, upgrade the Jenkins SWAMP Plugin to version 1.2.7 or later.
3
Who is affected by CVE-2022-25212?
CVE-2022-25212 affects users of the Jenkins SWAMP Plugin version 1.2.6 and earlier.
4
What can an attacker do using CVE-2022-25212?
An attacker exploiting CVE-2022-25212 can initiate requests to a specified web server using credentials supplied by the victim.
5
Is CVE-2022-25212 a widespread vulnerability?
CVE-2022-25212 is primarily relevant to users of the Jenkins SWAMP Plugin, which may limit its widespread impact.