CVE-2022-36908 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Jenkins OpenShift Deployer Plugin versions 1.2.0 and earlier. This medium-severity vulnerability (CVSS 6.5) allows unauthenticated attackers to check for arbitrary file paths on the Jenkins controller and upload SSH keys from the controller to an attacker-specified URL. While the vulnerability has a high impact on integrity, it requires user interaction and has no known public exploits, Metasploit modules, or community discussion, indicating a low current exploitation risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.2.0CPE matchmatch criteria | cpe:2.3:a:jenkins:openshift_deployer:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.