First published: Tue Nov 15 2022(Updated: )
A cross-site request forgery (CSRF) vulnerability in Jenkins Cluster Statistics Plugin 0.4.6 and earlier allows attackers to delete recorded Jenkins Cluster Statistics.
Credit: jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Cluster Statistics | <=0.4.6 | |
maven/org.zeroturnaround:cluster-stats | <=0.4.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-45398 is classified as a medium severity vulnerability.
To fix CVE-2022-45398, upgrade the Jenkins Cluster Statistics Plugin to version 0.4.7 or later.
CVE-2022-45398 allows attackers to delete recorded Jenkins Cluster Statistics through a cross-site request forgery (CSRF) exploit.
CVE-2022-45398 affects Jenkins Cluster Statistics Plugin version 0.4.6 and earlier.
Yes, CVE-2022-45398 poses a security risk as it allows unauthorized deletion of important statistics.