First published: Wed Jul 27 2022(Updated: )
A cross-site request forgery (CSRF) vulnerability in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers to check for the existence of an attacker-specified file path on the Jenkins controller file system and to upload a SSH key file from the Jenkins controller file system to an attacker-specified URL.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Openshift Deployer | <=1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36908 is considered to be a medium severity vulnerability due to its potential to allow unauthorized file access and SSH key uploads.
To fix CVE-2022-36908, update the Jenkins OpenShift Deployer Plugin to version 1.2.1 or later.
CVE-2022-36908 is a cross-site request forgery (CSRF) vulnerability.
CVE-2022-36908 affects Jenkins OpenShift Deployer Plugin version 1.2.0 and earlier.
Attackers exploiting CVE-2022-36908 can check for the existence of specified file paths and upload SSH key files from the Jenkins controller file system.