CVE-2022-43418: CSRF
A cross-site request forgery (CSRF) vulnerability in Jenkins Katalon Plugin 1.0.33 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-43418.
What is the title of the vulnerability?
The title of the vulnerability is 'A cross-site request forgery (CSRF) vulnerability in Jenkins Katalon Plugin 1.0.33 and earlier.'
What is the severity of CVE-2022-43418?
The severity of CVE-2022-43418 is medium with a severity value of 4.3.
What software versions are affected by CVE-2022-43418?
Jenkins Katalon Plugin versions up to but not including 1.0.34 are affected by CVE-2022-43418.
How can an attacker exploit CVE-2022-43418?
An attacker can exploit CVE-2022-43418 by connecting to an attacker-specified URL using attacker-specified credentials obtained through another method, capturing stored credentials in Jenkins.