CVE-2022-30972: CSRF
A cross-site request forgery (CSRF) vulnerability in Jenkins Storable Configs Plugin 1.0 and earlier allows attackers to have Jenkins parse a local XML file (e.g., archived artifacts) that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-30972?
CVE-2022-30972 is a cross-site request forgery (CSRF) vulnerability in the Jenkins Storable Configs Plugin.
How does CVE-2022-30972 affect Jenkins?
CVE-2022-30972 allows attackers to parse a local XML file with external entities to extract secrets from the Jenkins controller or perform server-side request forgery.
What is the severity of CVE-2022-30972?
The severity of CVE-2022-30972 is rated as high with a CVSS score of 8.8.
Which version of Jenkins Storable Configs Plugin is affected by CVE-2022-30972?
Jenkins Storable Configs Plugin version 1.0 and earlier are affected by CVE-2022-30972.
How can I mitigate CVE-2022-30972?
To mitigate CVE-2022-30972, it is recommended to upgrade to a version of Jenkins Storable Configs Plugin that is not affected by the vulnerability.