CVE-2022-25208

All FrameworksSinatraCWE-OtherCVE-2022-25208

CVE-2022-25208

State: PUBLISHED · Published: 2022-02-15 · Updated: 2024-08-03 · Assigner: jenkins
Description
A missing permission check in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers with Overall/Read permission to have Jenkins send an HTTP request to an attacker-controlled URL and have it parse an XML response.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2022/25xxx/CVE-2022-25208.json