CVE-2022-36920: CSRF
Published Jul 27, 2022
·Updated
A cross-site request forgery (CSRF) vulnerability in Jenkins Coverity Plugin 1.11.4 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Affected Software
1 affected component
Jenkins Coverity Jenkins<=1.11.4
Event History
Jul 27, 2022
CVE Published
via MITRE·02:29 PM
Data Sourced
via MITRE·02:29 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-36920?
CVE-2022-36920 is categorized as a medium severity vulnerability due to the potential for unauthorized access to Jenkins credentials.
2
How do I fix CVE-2022-36920?
To remediate CVE-2022-36920, upgrade the Jenkins Coverity Plugin to version 1.11.5 or later.
3
What systems are affected by CVE-2022-36920?
CVE-2022-36920 affects Jenkins Coverity Plugin versions 1.11.4 and earlier.
4
What can an attacker do with CVE-2022-36920?
An attacker exploiting CVE-2022-36920 can connect to a malicious URL and capture Jenkins credentials stored on the server.
5
When was CVE-2022-36920 disclosed?
CVE-2022-36920 was disclosed on July 27, 2022.