CVE-2022-41236 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Jenkins Security Inspector Plugin versions 117.v6eecc36919c2 and earlier. This vulnerability allows an attacker to manipulate the report displayed to authorized users by replacing it with one based on attacker-specified generation options. Rated with a CVSS score of 8.8 (High), it has a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 117.v6eecc36919c2CPE matchmatch criteria | cpe:2.3:a:jenkins:security_inspector:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.