VYPR
Moderate severityNVD Advisory· Published Jun 22, 2022· Updated Aug 3, 2024

CVE-2022-34203

CVE-2022-34203

Description

A CSRF vulnerability in Jenkins EasyQA Plugin 1.0 and earlier allows attackers to trick users into connecting to an attacker-controlled HTTP server.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A CSRF vulnerability in Jenkins EasyQA Plugin 1.0 and earlier allows attackers to trick users into connecting to an attacker-controlled HTTP server.

Vulnerability

Overview

CVE-2022-34203 is a cross-site request forgery (CSRF) vulnerability in the Jenkins EasyQA Plugin, affecting versions 1.0 and earlier. The plugin does not require a valid Jenkins session token for specific endpoints, allowing an attacker to craft a malicious request that, when executed by an authenticated Jenkins user, forces the Jenkins instance to connect to an attacker-specified HTTP server [1].

Exploitation

Details

To exploit this vulnerability, an attacker must trick a Jenkins user with sufficient permissions into clicking a crafted link or visiting a malicious page. No other privileges are required beyond the victim being logged into Jenkins. The attack is network-based and can be launched remotely, as the attacker only needs to lure the victim to a crafted URL that triggers the forged request [1][3].

Impact

If exploited, an attacker can cause the Jenkins server to connect to an arbitrary HTTP server under the attacker's control. This can be used for reconnaissance (e.g., verifying the internal network) or as part of a multi-step attack to exfiltrate data or pivot to other internal systems. The vulnerability does not grant direct command execution but can aid further exploitation [1].

Mitigation

As of the Jenkins Security Advisory 2022-06-22, no patch was available for the EasyQA Plugin; users are advised to discontinue use of the plugin if it is no longer maintained, as the plugin may be EOL [1][2]. The vulnerability is not known to be exploited in the wild, but users should review their usage of the plugin and consider removing it to reduce risk [3].

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
com.geteasyqa:easyqaMaven
<= 1.0

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.