CVE-2022-41227: CSRF
A cross-site request forgery (CSRF) vulnerability in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers to connect to an attacker-specified webserver using attacker-specified credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-41227?
CVE-2022-41227 has been classified as a medium severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2022-41227?
To mitigate CVE-2022-41227, upgrade to the Jenkins NS-ND Integration Performance Publisher Plugin version 4.8.0.130 or later.
What impact does CVE-2022-41227 have on my Jenkins instance?
CVE-2022-41227 allows attackers to perform unauthorized actions on behalf of users, potentially leading to data breaches.
Is CVE-2022-41227 exploitable without user interaction?
Yes, CVE-2022-41227 can be exploited via CSRF attacks, allowing attackers to send requests without user consent.
What versions of the Jenkins NS-ND Integration Performance Publisher Plugin are affected by CVE-2022-41227?
CVE-2022-41227 affects versions 4.8.0.129 and earlier of the Jenkins NS-ND Integration Performance Publisher Plugin.