// For flags

CVE-2022-27198

 

Severity Score

8.0
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A cross-site request forgery (CSRF) vulnerability in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers with Overall/Read permission to connect to an AWS service using an attacker-specified token.

Una vulnerabilidad de tipo cross-site request forgery (CSRF) en el plugin Jenkins CloudBees AWS Credentials versiones 189.v3551d5642995 y anteriores, permite a atacantes con permiso Overall/Read conectarse a un servicio de AWS usando un token especificado por el atacante

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-03-15 CVE Reserved
  • 2022-03-15 CVE Published
  • 2023-10-06 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Jenkins
Search vendor "Jenkins"
Cloudbees Aws Credentials
Search vendor "Jenkins" for product "Cloudbees Aws Credentials"
<= 189.v3551d5642995
Search vendor "Jenkins" for product "Cloudbees Aws Credentials" and version " <= 189.v3551d5642995"
jenkins
Affected
Jenkins
Search vendor "Jenkins"
Cloudbees Aws Credentials
Search vendor "Jenkins" for product "Cloudbees Aws Credentials"
>= 1.28 < 1.28.2
Search vendor "Jenkins" for product "Cloudbees Aws Credentials" and version " >= 1.28 < 1.28.2"
jenkins
Affected
Jenkins
Search vendor "Jenkins"
Cloudbees Aws Credentials
Search vendor "Jenkins" for product "Cloudbees Aws Credentials"
1.32
Search vendor "Jenkins" for product "Cloudbees Aws Credentials" and version "1.32"
jenkins
Affected