LiveActive security incident?Get immediate response
CVE Record

CVE-2022-41232: A cross-site request forgery (CSRF) vulnerability in Jenkins Build-Publisher Plugin 1.22 and earlier allows...

A cross-site request forgery (CSRF) vulnerability in Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers to replace any config.xml file on the Jenkins controller file system with an empty file by providing a crafted file name to an API endpoint.

HighCVSS 8Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

Jenkins Build-Publisher Plugin 1.22 and earlier has a CSRF flaw that can let an attacker trick a logged-in Jenkins user into causing serious controller configuration damage. The reported impact is replacing any config.xml file on the Jenkins controller filesystem with an empty file, which can disrupt jobs or Jenkins behavior.

Executive priority

Treat this as high priority for Jenkins environments using the affected plugin. It can damage central CI/CD configuration, potentially interrupting delivery pipelines and weakening operational control, even though active exploitation is not evidenced in the provided sources.

Technical view

The issue is CWE-352 in a Build-Publisher Plugin API endpoint. With network access, low privileges, and user interaction, an attacker can supply a crafted file name that causes arbitrary Jenkins controller config.xml files to be emptied. CVSS 3.1 is 8.0 with high confidentiality, integrity, and availability impact.

Likely exposure

Exposure is limited to Jenkins environments running Build-Publisher Plugin 1.22 or earlier. Risk is higher where Jenkins is reachable by many users, where low-privileged accounts exist, or where administrators may browse attacker-controlled pages while authenticated to Jenkins.

Exploitation context

The source bundle does not show CISA KEV listing or cited active exploitation. Exploitation requires user interaction and at least low privileges, but the potential outcome is severe because Jenkins controller configuration files can be destroyed.

Researcher notes

Key constraints are CSRF, required user interaction, and low privileges per CVSS. The most important exposure question is whether Build-Publisher Plugin 1.22 or earlier is installed. The provided evidence does not establish a fixed version, exploit publication, or active exploitation.

Mitigation direction

  • Inventory Jenkins instances for Build-Publisher Plugin version 1.22 or earlier.
  • Review the Jenkins advisory and plugin release notes for vendor-supported remediation.
  • Restrict Jenkins access to trusted users and networks while remediation is assessed.
  • Back up Jenkins controller configuration before making plugin or platform changes.
  • Remove or disable unnecessary vulnerable plugin use where business impact permits.

Validation and detection

  • Check installed Jenkins plugins and confirm whether Build-Publisher is present.
  • Record the installed Build-Publisher Plugin version on each Jenkins controller.
  • Confirm whether Jenkins controller config.xml backups exist and can be restored.
  • Review Jenkins access logs for suspicious API activity around the plugin.
  • Verify remediation against the Jenkins advisory before closing the finding.
Prepared
Confidence
high
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-352: User-session and phishing behavior lookup

Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2022-41232 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
8 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
8CVSS 3.1HighCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H2.15.9Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

8High
CVSS 3.1 vector shape for CVE-2022-41232Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Jenkins projectJenkins Build-Publisher Pluginunspecified, next of 1.22Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-352 · source CWE mapping

Cross-Site Request Forgery (CSRF)

Cross-Site Request Forgery (CSRF) represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.