Description
A cross-site request forgery (CSRF) vulnerability in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers to connect to an attacker-specified webserver using attacker-specified credentials.
Remediation
References
https://www.jenkins.io/security/advisory/2022-09-21/#SECURITY-2737
Related Vulnerabilities
CVE-2022-42252 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2021-46877 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2019-12421 Vulnerability in maven package org.apache.nifi:nifi-web-security
CVE-2020-9482 Vulnerability in maven package org.apache.nifi.registry:nifi-registry-core