{"id":"CVE-2022-43408","aliases":[],"url":"https://o3.security/vulnerability/CVE-2022-43408","summary":"Jenkins Pipeline: Stage View Plugin allows CSRF protection bypass of any target URL in Jenkins","details":"Jenkins Pipeline: Stage View Plugin provides a visualization of Pipeline builds. It also allows users to interact with `input` steps from Pipeline: Input Step Plugin.\n\nPipeline: Stage View Plugin 2.26 and earlier does not correctly encode the ID of `input` steps when using it to generate URLs to proceed or abort Pipeline builds.\n\nThis allows attackers able to configure Pipelines to specify `input` step IDs resulting in URLs that would bypass the CSRF protection of any target URL in Jenkins.\n\nPipeline: Stage View Plugin 2.27 correctly encodes the ID of `input` steps when using it to generate URLs to proceed or abort Pipeline builds.","published":"2022-10-19T19:00:18Z","modified":"2024-02-16T08:24:10.335327Z","cvss":{"score":8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"},"epss":{"score":0.00472,"percentile":0.39811,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.jenkins-ci.plugins.pipeline-stage-view:pipeline-stage-view","fixedVersion":"2.27"},{"ecosystem":"Maven","name":"org.jenkins-ci.plugins.pipeline-stage-view:pipeline-stage-view","fixedVersion":"2.24.2"}],"fix":{"url":"https://github.com/jenkinsci/pipeline-stage-view-plugin/commit/cee275109ee748fa9f599ec60159807a28a2933f","label":"jenkinsci/pipeline-stage-view-plugin@cee2751"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-43408"},{"type":"WEB","url":"https://github.com/jenkinsci/pipeline-stage-view-plugin/commit/cee275109ee748fa9f599ec60159807a28a2933f"},{"type":"WEB","url":"https://www.jenkins.io/security/advisory/2022-10-19/#SECURITY-2828"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2022/10/19/3"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-02-16T08:24:10.335327Z"}}