Vulnerabilities > Jenkins > Chef Sinatra > High

DATE CVE VULNERABILITY TITLE RISK
2022-02-15 CVE-2022-25207 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Chef Sinatra
A cross-site request forgery (CSRF) vulnerability in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers to have Jenkins send an HTTP request to an attacker-controlled URL and have it parse an XML response.
network
low complexity
jenkins CWE-352
8.8
2022-02-15 CVE-2022-25208 Missing Authorization vulnerability in Jenkins Chef Sinatra
A missing permission check in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers with Overall/Read permission to have Jenkins send an HTTP request to an attacker-controlled URL and have it parse an XML response.
network
low complexity
jenkins CWE-862
8.8
2022-02-15 CVE-2022-25209 XXE vulnerability in Jenkins Chef Sinatra
Jenkins Chef Sinatra Plugin 1.20 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins CWE-611
8.8