{"id":"GHSA-m82g-fv7v-h64m","summary":"Jenkins Sonar Gerrit Plugin vulnerable to Cross-Site Request Forgery","details":"A cross-site request forgery (CSRF) vulnerability in Jenkins Sonar Gerrit Plugin 377.v8f3808963dc5 and earlier allows attackers to have Jenkins connect to Gerrit servers (previously configured by Jenkins administrators) using attacker-specified credentials IDs obtained through another method, potentially capturing credentials stored in Jenkins.","aliases":["CVE-2022-46688"],"modified":"2024-02-16T08:18:26.938301Z","published":"2022-12-12T09:30:35Z","database_specific":{"cwe_ids":["CWE-352"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-12-12T22:08:48Z","nvd_published_at":"2022-12-12T09:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-46688"},{"type":"WEB","url":"https://github.com/jenkinsci/sonar-gerrit-plugin/commit/f4646d4df0870bd06b76de86309bb38fbd929d54"},{"type":"PACKAGE","url":"https://github.com/jenkinsci/sonar-gerrit-plugin"},{"type":"WEB","url":"https://www.jenkins.io/security/advisory/2022-12-07/#SECURITY-1002"}],"affected":[{"package":{"name":"org.jenkins-ci.plugins:sonar-gerrit","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins/sonar-gerrit"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"378.vf4646d4df087"}]}],"versions":["1.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7.6","1.0.8","2.0","2.1","2.2.1","2.3","2.4.3","2.4.4","2.4.5","2.4.6","348.v33583c89a_a_b_4","350.v9b_a_6a_3e3196e","351.vb_8d85df69260","353.v20e9cff705d1","361.v3f45367a_71da_","362.v43a_b_52a_b_23a_5","363.v95109f2b_9d0d","366.vdb_8f26406e04","368.vb_a_b_e20a_b_6a_b_d","369.vc4ff5c47910b_","370.vf2cf40f43d41","371.v7f34ee88b_960","375.v1b_e7dfc25ed0","376.v67dc39df1298","377.v8f3808963dc5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/12/GHSA-m82g-fv7v-h64m/GHSA-m82g-fv7v-h64m.json","last_known_affected_version_range":"\u003c= 377.v8f3808963dc5"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"}]}