{"id":"CVE-2022-46688","details":"A cross-site request forgery (CSRF) vulnerability in Jenkins Sonar Gerrit Plugin 377.v8f3808963dc5 and earlier allows attackers to have Jenkins connect to Gerrit servers (previously configured by Jenkins administrators) using attacker-specified credentials IDs obtained through another method, potentially capturing credentials stored in Jenkins.","aliases":["GHSA-m82g-fv7v-h64m"],"modified":"2026-07-09T05:17:57.598582Z","published":"2022-12-12T09:15:13.247Z","references":[{"type":"ADVISORY","url":"https://www.jenkins.io/security/advisory/2022-12-07/#SECURITY-1002"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/jenkinsci/sonar-gerrit-plugin","events":[{"introduced":"0"},{"last_affected":"8f3808963dc55315676746aef0705b6cae5b559c"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"377.v8f3808963dc5"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:jenkins:sonar_gerrit:*:*:*:*:*:jenkins:*:*"}}],"versions":["377.v8f3808963dc5","376.v67dc39df1298","375.v1b_e7dfc25ed0","371.v7f34ee88b_960","370.vf2cf40f43d41","369.vc4ff5c47910b_","368.vb_a_b_e20a_b_6a_b_d","366.vdb_8f26406e04","363.v95109f2b_9d0d","362.v43a_b_52a_b_23a_5","361.v3f45367a_71da_","353.v20e9cff705d1","351.vb_8d85df69260","350.v9b_a_6a_3e3196e","348.v33583c89a_a_b_4","sonar-gerrit-2.4.6","sonar-gerrit-2.4.5","sonar-gerrit-2.4.4","sonar-gerrit-2.4.3","sonar-gerrit-2.4.2","sonar-gerrit-2.4.1","sonar-gerrit-2.4","sonar-gerrit-2.3","sonar-gerrit-2.2.1","sonar-gerrit-2.2","sonar-gerrit-2.1","sonar-gerrit-1.0.8","sonar-gerrit-1.0.6","sonar-gerrit-1.0.5","sonar-gerrit-1.0.4","sonar-gerrit-1.0.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-46688.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"}]}