
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-41236 is a Cross-Site Request Forgery (CSRF) vulnerability discovered in the Jenkins Security Inspector Plugin version 117.v6eecc36919c2 and earlier. The vulnerability was disclosed on September 21, 2022, affecting the Security Inspector Plugin's report generation functionality (Jenkins Advisory).
The vulnerability stems from the plugin's failure to require POST requests for an HTTP endpoint. The affected component is specifically the report generation functionality at the '.../report' URL. The severity is rated as Medium according to CVSS scoring system (Jenkins Advisory).
The vulnerability allows attackers to replace the generated report stored in a per-session cache that is displayed to authorized users. The manipulated report would be based on attacker-specified report generation options, potentially creating confusion for users expecting to see different results (Jenkins Advisory).
As of the advisory's publication date, no fix was available for this vulnerability in the Security Inspector Plugin. The partial mitigation exists through Jenkins core security hardening for specific report types, but a complete fix was not released (Jenkins Advisory).
The vulnerability was discovered and reported by Jeff Thompson from CloudBees, Inc., highlighting the ongoing security research efforts within the Jenkins ecosystem (Jenkins Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."