PT-2022-18846 · Unknown+1 · Toad Edge Plugin+1

Kevin Guerroudj

·

Published

2022-03-29

·

Updated

2023-11-17

·

CVE-2022-28147

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Continuous Integration with Toad Edge Plugin versions 2.3 and earlier
Description A missing permission check allows attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.
Recommendations For versions 2.3 and earlier, update to a version that includes the missing permission check to prevent attackers from checking the existence of arbitrary file paths on the Jenkins controller file system. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Improper Preservation of Permissions

Weakness Enumeration

Related Identifiers

CVE-2022-28147
GHSA-8HH2-RXM8-7FJ8

Affected Products

Jenkins
Toad Edge Plugin