First published: Thu Jun 30 2022(Updated: )
A cross-site request forgery (CSRF) vulnerability in Jenkins Failed Job Deactivator Plugin 1.2.1 and earlier allows attackers to disable jobs.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Failed Job Deactivator | <=1.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-34817 is classified as medium.
To fix CVE-2022-34817, update the Jenkins Failed Job Deactivator Plugin to version 1.2.2 or later.
CVE-2022-34817 is a cross-site request forgery (CSRF) vulnerability.
Attackers exploiting CVE-2022-34817 can disable jobs in Jenkins.
CVE-2022-34817 affects Jenkins Failed Job Deactivator Plugin versions 1.2.1 and earlier.