Description
A cross-site request forgery (CSRF) vulnerability in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers to connect to an attacker-specified database via JDBC using attacker-specified credentials and to determine if a class is available in the Jenkins instance.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1219 | A cross-site request forgery (CSRF) vulnerability in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers to connect to an attacker-specified database via JDBC using attacker-specified credentials and to determine if a class is available in the Jenkins instance. |
Github GHSA |
GHSA-vx6f-6rp6-f2px | Cross-Site Request Forgery in Jenkins dbCharts Plugin |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-03T04:36:06.646Z
Reserved: 2022-02-15T00:00:00.000Z
Link: CVE-2022-25205
No data.
Status : Modified
Published: 2022-02-15T17:15:11.107
Modified: 2024-11-21T06:51:48.310
Link: CVE-2022-25205
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA