Jenkins Pipeline: Stage View Plugin 2.26 and earlier does not correctly encode the ID of 'input' steps when using it to generate URLs to proceed or abort Pipeline builds, allowing attackers able to configure Pipelines to specify 'input' step IDs resulting in URLs that would bypass the CSRF protection of any target URL in Jenkins.
                
            References
                    | Link | Resource | 
|---|---|
| http://www.openwall.com/lists/oss-security/2022/10/19/3 | Mailing List Third Party Advisory | 
| https://www.jenkins.io/security/advisory/2022-10-19/#SECURITY-2828 | Vendor Advisory | 
| http://www.openwall.com/lists/oss-security/2022/10/19/3 | Mailing List Third Party Advisory | 
| https://www.jenkins.io/security/advisory/2022-10-19/#SECURITY-2828 | Vendor Advisory | 
Configurations
                    History
                    No history.
Information
                Published : 2022-10-19 16:15
Updated : 2025-05-08 20:15
NVD link : CVE-2022-43408
Mitre link : CVE-2022-43408
CVE.ORG link : CVE-2022-43408
JSON object : View
Products Affected
                jenkins
- pipeline\
CWE
                
                    
                        
                        CWE-352
                        
            Cross-Site Request Forgery (CSRF)
