PT-2022-22042 · Jenkins · Jenkins
Yaroslav Afenkin
·
Published
2022-06-22
·
Updated
2024-03-06
·
CVE-2022-34175
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins versions 2.335 through 2.355
Description
The issue allows attackers in some cases to bypass a protection mechanism, directly accessing view fragments containing sensitive information and bypassing permission checks in the corresponding view. This occurs because the protection added for a previous security issue is disabled for some views in the affected versions. The Jenkins security team is unaware of any vulnerable view fragment across the Jenkins plugin ecosystem.
Recommendations
For versions 2.335 through 2.355, update to version 2.356 or later to restore the protection for affected views. As a temporary workaround, consider restricting access to sensitive view fragments until the issue is resolved.
Fix
Protection Mechanism Failure
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins