PT-2022-18846 · Unknown+1 · Toad Edge Plugin+1
Kevin Guerroudj
·
Published
2022-03-29
·
Updated
2023-11-17
·
CVE-2022-28147
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Continuous Integration with Toad Edge Plugin versions 2.3 and earlier
Description
A missing permission check allows attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.
Recommendations
For versions 2.3 and earlier, update to a version that includes the missing permission check to prevent attackers from checking the existence of arbitrary file paths on the Jenkins controller file system.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authorization
Improper Preservation of Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins
Toad Edge Plugin