A cross-site request forgery (CSRF) vulnerability in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers with Overall/Read permission to connect to an AWS service using an attacker-specified token.
2022-03-15T17:15:10.190
2024-11-21T06:55:23.600
Modified
CVSSv3.1: 8.0 (HIGH)
AV:N/AC:M/Au:S/C:P/I:P/A:P
6.8
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | jenkins | cloudbees_aws_credentials | ≤ 189.v3551d5642995 | Yes |
| Application | jenkins | cloudbees_aws_credentials | < 1.28.2 | Yes |
| Application | jenkins | cloudbees_aws_credentials | 1.32 | Yes |