Jenkins Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in the HTTP endpoint it provides for "unprotected" status badge access, allowing attackers without any permissions to obtain the build status badge icon for any attacker-specified job and/or build.
References
Link | Resource |
---|---|
https://www.jenkins.io/security/advisory/2022-06-22/#SECURITY-2794 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: jenkins
Published: 2022-06-22T14:41:06
Updated: 2023-10-24T14:22:24.121Z
Reserved: 2022-06-21T00:00:00
Link: CVE-2022-34180
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-06-23T17:15:15.867
Modified: 2023-11-03T18:21:03.327
Link: CVE-2022-34180
JSON object: View
Redhat Information
No data.
CWE