Jenkins Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in the HTTP endpoint it provides for "unprotected" status badge access, allowing attackers without any permissions to obtain the build status badge icon for any attacker-specified job and/or build.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: jenkins

Published: 2022-06-22T14:41:06

Updated: 2023-10-24T14:22:24.121Z

Reserved: 2022-06-21T00:00:00


Link: CVE-2022-34180

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-06-23T17:15:15.867

Modified: 2023-11-03T18:21:03.327


Link: CVE-2022-34180

JSON object: View

cve-icon Redhat Information

No data.

CWE