SCA: security update for org.jenkins-ci.plugins:pipeline-input-step (GHSA-g66m-fqxf-3w35)

high Tenable Self-Hosted Container Security Plugin ID 414925

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Jenkins Pipeline: Input Step Plugin 451.vf1a_a_4f405289 and earlier does not restrict or sanitize the
optionally specified ID of the 'input' step, which is used for the URLs that process user interactions for
the given 'input' step (proceed or abort) and is not correctly encoded, allowing attackers able to
configure Pipelines to have Jenkins build URLs from 'input' step IDs that would bypass the CSRF protection
of any target URL in Jenkins when the 'input' step is interacted with. (CVE-2022-43407)

See Also

https://github.com/advisories/GHSA-g66m-fqxf-3w35

Plugin Details

Severity: High

ID: 414925

Version: Revision 1.11

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.12

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2022-43407

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/19/2022

Vulnerability Publication Date: 10/19/2022

Reference Information

CVE: CVE-2022-43407