CVE-2022-30946

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-30946
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-30946.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-30946
Aliases
Downstream
Published
2022-05-17T15:15:08Z
Modified
2025-10-15T13:57:51.970114Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N CVSS Calculator
Summary
[none]
Details

A cross-site request forgery (CSRF) vulnerability in Jenkins Script Security Plugin 1158.v7c1b73a69a_08 and earlier allows attackers to have Jenkins send an HTTP request to an attacker-specified webserver.

References

Affected packages

Git / github.com/jenkinsci/script-security-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/script-security-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1118.*

1118.vba21ca2e3286

1125.*

1125.v132f99385e1b_

1131.*

1131.v8b_b_5eda_c328e

1138.*

1138.v8e727069a_025

1140.*

1140.vf967fb_efa_55a_

1145.*

1145.vb_cf6cf6ed960

1146.*

1146.vdf547f19a_473

1158.*

1158.v7c1b_73a_69a_08

script-security-1.*

script-security-1.0
script-security-1.0-beta-1
script-security-1.0-beta-2
script-security-1.0-beta-3
script-security-1.0-beta-4
script-security-1.0-beta-5
script-security-1.0-beta-6
script-security-1.1
script-security-1.10
script-security-1.11
script-security-1.12
script-security-1.13
script-security-1.14
script-security-1.15
script-security-1.16
script-security-1.17
script-security-1.18
script-security-1.19
script-security-1.2
script-security-1.20
script-security-1.21
script-security-1.22
script-security-1.23
script-security-1.24
script-security-1.25
script-security-1.26
script-security-1.27
script-security-1.28
script-security-1.29
script-security-1.3
script-security-1.30
script-security-1.31
script-security-1.32
script-security-1.33
script-security-1.34
script-security-1.35
script-security-1.36
script-security-1.37
script-security-1.38
script-security-1.39
script-security-1.4
script-security-1.40
script-security-1.41
script-security-1.42
script-security-1.43
script-security-1.44
script-security-1.45
script-security-1.46
script-security-1.47
script-security-1.48
script-security-1.49
script-security-1.5
script-security-1.50
script-security-1.51
script-security-1.52
script-security-1.53
script-security-1.54
script-security-1.55
script-security-1.56
script-security-1.57
script-security-1.58
script-security-1.59
script-security-1.6
script-security-1.60
script-security-1.61
script-security-1.62
script-security-1.63
script-security-1.64
script-security-1.65
script-security-1.66
script-security-1.67
script-security-1.68
script-security-1.69
script-security-1.7
script-security-1.70
script-security-1.71
script-security-1.72
script-security-1.73
script-security-1.74
script-security-1.75
script-security-1.76
script-security-1.77
script-security-1.78
script-security-1.8
script-security-1.9

Database specific

vanir_signatures

[
    {
        "deprecated": false,
        "target": {
            "file": "src/main/java/org/jenkinsci/plugins/scriptsecurity/scripts/ScriptApproval.java",
            "function": "checking"
        },
        "signature_version": "v1",
        "source": "https://github.com/jenkinsci/script-security-plugin/commit/35f6a0b8207ed3a32a85f27c1312da6cd738eeaa",
        "digest": {
            "function_hash": "243053922828200876436764045460028826147",
            "length": 604.0
        },
        "signature_type": "Function",
        "id": "CVE-2022-30946-70a50d2d"
    },
    {
        "deprecated": false,
        "target": {
            "file": "src/main/java/org/jenkinsci/plugins/scriptsecurity/scripts/ScriptApproval.java"
        },
        "signature_version": "v1",
        "source": "https://github.com/jenkinsci/script-security-plugin/commit/35f6a0b8207ed3a32a85f27c1312da6cd738eeaa",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "247190495179758266572481066570786804673",
                "167999783080315131500261662791942509463",
                "121267700977726733791167484452692597670",
                "39917716663608181141736465198567593231",
                "289597266990881468480631836825524301844",
                "236055391751122233183289647518514099902",
                "150825002549546166225446775241610946125",
                "500911795054415170633374521061405029",
                "280819062623828007514179088577183876334",
                "84070120999375605160030220347455786089",
                "223137633455318029423863477277013203959",
                "250733090564975443232259021468433703349",
                "269250703096076647657600985504105281709",
                "198601851934786616786394872181445693666",
                "238475456578126862093474237346476679751",
                "214242453646278936544984494447735434029",
                "300657914692014166977767370373596327484",
                "339215527704213608801660788207473458661",
                "8964003737450922026086742804177696289",
                "282243120677463312286873005183975868761",
                "64865270473693994228611861625137348886",
                "312354628292864390096562044962419924767"
            ]
        },
        "signature_type": "Line",
        "id": "CVE-2022-30946-efe5679d"
    }
]