CVE-2022-43408: CSRF

Published Oct 19, 2022
·
Updated

A Cross-site request forgery (CSRF) vulnerability was found in a Jenkins plugin. This issue may allow an authenticated attacker to access Jenkins builds, bypassing CSRF protections.

Other sources

Jenkins Pipeline: Stage View Plugin 2.26 and earlier does not correctly encode the ID of 'input' steps when using it to generate URLs to proceed or abort Pipeline builds, allowing attackers able to configure Pipelines to specify 'input' step IDs resulting in URLs that would bypass the CSRF protection of any target URL in Jenkins.

Jenkins Pipeline: Stage View Plugin provides a visualization of Pipeline builds. It also allows users to interact with input steps from Pipeline: Input Step Plugin.

Pipeline: Stage View Plugin 2.26 and earlier does not correctly encode the ID of input steps when using it to generate URLs to proceed or abort Pipeline builds.

This allows attackers able to configure Pipelines to specify input step IDs resulting in URLs that would bypass the CSRF protection of any target URL in Jenkins.

Pipeline: Stage View Plugin 2.27 correctly encodes the ID of input steps when using it to generate URLs to proceed or abort Pipeline builds.

Affected Software

9 affected componentsFixes available
redhat/jenkins<2-plugins-0:4.11.1683009941-1.el8
2-plugins-0:4.11.1683009941-1.el8
redhat/jenkins<2-plugins-0:4.12.1675702407-1.el8
2-plugins-0:4.12.1675702407-1.el8
redhat/jenkins<2-plugins-0:4.10.1675144701-1.el8
2-plugins-0:4.10.1675144701-1.el8
redhat/jenkins<2-plugins-0:4.9.1675668922-1.el8
2-plugins-0:4.9.1675668922-1.el8
Jenkins Stage View Jenkins<=2.26
maven/org.jenkins-ci.plugins.pipeline-stage-view:pipeline-stage-view>=2.25<2.27
2.27
maven/org.jenkins-ci.plugins.pipeline-stage-view:pipeline-stage-view<2.24.2
2.24.2
redhat/Pipeline Stage View Plugin<2.27
2.27
Jenkins Pipeline\<2.27

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/jenkins to a version that resolves this vulnerability.

    Fixed in 2-plugins-0:4.11.1683009941-1.el8
  2. Upgrade

    Upgrade redhat/jenkins to a version that resolves this vulnerability.

    Fixed in 2-plugins-0:4.12.1675702407-1.el8
  3. Upgrade

    Upgrade redhat/jenkins to a version that resolves this vulnerability.

    Fixed in 2-plugins-0:4.10.1675144701-1.el8
  4. Upgrade

    Upgrade redhat/jenkins to a version that resolves this vulnerability.

    Fixed in 2-plugins-0:4.9.1675668922-1.el8
  5. Upgrade

    Upgrade maven/org.jenkins-ci.plugins.pipeline-stage-view:pipeline-stage-view to a version that resolves this vulnerability.

    Fixed in 2.27
  6. Upgrade

    Upgrade maven/org.jenkins-ci.plugins.pipeline-stage-view:pipeline-stage-view to a version that resolves this vulnerability.

    Fixed in 2.24.2
  7. Upgrade

    Upgrade redhat/Pipeline Stage View Plugin to a version that resolves this vulnerability.

    Fixed in 2.27
  8. Upgrade

    Upgrade Jenkins Pipeline: Stage View Plugin to a version that resolves this vulnerability.

    Fixed in 2.27
  9. Compensating control

    Apply the Jenkins advisory’s CSRF mitigation for SECURITY-2828 by ensuring attackers cannot reach the proceed/abort URL endpoints (e.g., restrict access to Jenkins/Build URLs to trusted users and networks) until the affected plugin is upgraded to 2.27.

Event History

Oct 19, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
07:00 PM
Oct 20, 2022
Data Sourced
via Red Hat·06:53 AM
DescriptionSeverityAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2022-43408?

CVE-2022-43408 is classified as a medium severity vulnerability due to its potential for unauthenticated access to sensitive builds.

2

How do I fix CVE-2022-43408?

To fix CVE-2022-43408, upgrade the Jenkins Pipeline: Stage View Plugin to version 2.27 or later.

3

What versions are affected by CVE-2022-43408?

CVE-2022-43408 affects versions 2.26 and earlier of the Jenkins Pipeline: Stage View Plugin.

4

Can CVE-2022-43408 be exploited remotely?

CVE-2022-43408 requires an authenticated attacker to exploit the vulnerability.

5

Is there a patch for CVE-2022-43408?

Yes, a patch is available by updating to Jenkins Pipeline: Stage View Plugin version 2.27 or higher.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203