CVE-2022-46688: CSRF
A cross-site request forgery (CSRF) vulnerability in Jenkins Sonar Gerrit Plugin 377.v8f3808963dc5 and earlier allows attackers to have Jenkins connect to Gerrit servers (previously configured by Jenkins administrators) using attacker-specified credentials IDs obtained through another method, potentially capturing credentials stored in Jenkins.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-46688?
CVE-2022-46688 is classified as a high severity cross-site request forgery (CSRF) vulnerability.
How do I fix CVE-2022-46688?
To fix CVE-2022-46688, upgrade the Jenkins Sonar Gerrit Plugin to version 378.vf4646d4df087 or later.
What impact does CVE-2022-46688 have on Jenkins?
CVE-2022-46688 allows attackers to control connections to Gerrit servers using unauthorized credentials, compromising the integrity of Jenkins.
Who is affected by CVE-2022-46688?
All users of Jenkins Sonar Gerrit Plugin versions up to 377.v8f3808963dc5 are affected by CVE-2022-46688.
Is there a workaround for CVE-2022-46688?
Currently, there is no documented workaround for CVE-2022-46688, so upgrading the plugin is the recommended action.