CVE-2022-34211: CSRF
Published Jun 22, 2022
·Updated
A cross-site request forgery (CSRF) vulnerability in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers to send an HTTP POST request to an attacker-specified URL.
Affected Software
1 affected component
Jenkins Vrealize Orchestrator Jenkins<=3.0
Event History
Jun 22, 2022
CVE Published
via MITRE·02:41 PM
Data Sourced
via MITRE·02:41 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-34211.
2
What is the severity of CVE-2022-34211?
The severity of CVE-2022-34211 is medium with a CVSS score of 6.5.
3
Which software versions are affected by CVE-2022-34211?
Jenkins vRealize Orchestrator Plugin versions up to and including 3.0 are affected by CVE-2022-34211.
4
What is the description of CVE-2022-34211?
CVE-2022-34211 is a cross-site request forgery (CSRF) vulnerability in Jenkins vRealize Orchestrator Plugin 3.0 and earlier, which allows attackers to send an HTTP POST request to an attacker-specified URL.
5
How can I fix CVE-2022-34211?
To fix CVE-2022-34211, it is recommended to update Jenkins vRealize Orchestrator Plugin to a version higher than 3.0.