CVE-2022-45393
Description
CSRF vulnerability in Jenkins Delete log Plugin allows attackers to delete build logs.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CSRF vulnerability in Jenkins Delete log Plugin allows attackers to delete build logs.
A cross-site request forgery (CSRF) vulnerability exists in the Jenkins Delete log Plugin, affecting version 1.0 and earlier. The plugin does not implement any CSRF protection for its endpoint that deletes build logs, allowing an attacker to craft a malicious request that, when executed by an authenticated Jenkins user, deletes build logs without their knowledge [1].
To exploit this vulnerability, an attacker must trick a logged-in Jenkins user into visiting a malicious web page or clicking a crafted link. The user's browser then automatically sends the forged request to the Jenkins server, leveraging the user's session. No additional authentication is needed as the request is made in the context of the victim's session [2].
A successful exploit allows an attacker to delete build logs from Jenkins jobs. This can disrupt auditing, remove evidence of previous builds, or cause confusion in the CI/CD pipeline. The impact is limited to log deletion, but it can affect traceability and monitoring [1][2].
As of the advisory date (2022-11-15), no fix has been released for the Delete log Plugin. The plugin is likely unmaintained. Users are advised to either remove the plugin if not needed or implement a workaround such as restricting access via Jenkins' authorization mechanisms or proxying the Jenkins interface through a web application firewall [1].
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:delete-log-pluginMaven | <= 1.0 | — |
Affected products
2- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/advisories/GHSA-hw4f-g7wh-xp52ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-45393ghsaADVISORY
- www.openwall.com/lists/oss-security/2022/11/15/4ghsamailing-listWEB
- www.jenkins.io/security/advisory/2022-11-15/ghsaWEB
News mentions
1- Jenkins Security Advisory 2022-11-15Jenkins Security Advisories · Nov 15, 2022