First published: Thu Jun 30 2022(Updated: )
A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Xebialabs Xl Release | <=22.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34780 is a cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier, which allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
CVE-2022-34780 has a severity rating of 6.5, which is considered medium.
CVE-2022-34780 affects Jenkins XebiaLabs XL Release Plugin versions up to and including 22.0.0.
An attacker can exploit CVE-2022-34780 by leveraging a CSRF attack to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method.
Yes, a fix is available for CVE-2022-34780. It is recommended to update Jenkins XebiaLabs XL Release Plugin to a version that is not affected by this vulnerability.