CVE-2022-30946: CSRF
A cross-site request forgery (CSRF) vulnerability in Jenkins Script Security Plugin 1158.v7c1b73a69a08 and earlier allows attackers to have Jenkins send an HTTP request to an attacker-specified webserver.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2022-30946?
CVE-2022-30946 is considered a high severity vulnerability due to its ability to allow attackers to send unauthorized HTTP requests.
How do I fix CVE-2022-30946?
To address CVE-2022-30946, upgrade to the version of Jenkins Script Security Plugin that is higher than 1172.v35f6a_0b_8207e.
Which versions of Jenkins are affected by CVE-2022-30946?
CVE-2022-30946 affects Jenkins Script Security Plugin versions 1158.v7c1b_73a_69a_08 and earlier.
What type of vulnerability is CVE-2022-30946?
CVE-2022-30946 is a cross-site request forgery (CSRF) vulnerability.
Can CVE-2022-30946 lead to data breaches?
Yes, CVE-2022-30946 can potentially lead to data breaches as it enables attackers to make unauthorized requests on behalf of an authenticated user.