PT-2022-22042 · Jenkins · Jenkins

Yaroslav Afenkin

·

Published

2022-06-22

·

Updated

2024-03-06

·

CVE-2022-34175

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins versions 2.335 through 2.355
Description The issue allows attackers in some cases to bypass a protection mechanism, directly accessing view fragments containing sensitive information and bypassing permission checks in the corresponding view. This occurs because the protection added for a previous security issue is disabled for some views in the affected versions. The Jenkins security team is unaware of any vulnerable view fragment across the Jenkins plugin ecosystem.
Recommendations For versions 2.335 through 2.355, update to version 2.356 or later to restore the protection for affected views. As a temporary workaround, consider restricting access to sensitive view fragments until the issue is resolved.

Fix

Protection Mechanism Failure

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-JENKINS-2022-34175
CVE-2022-34175
GHSA-P3RC-946H-8CF5

Affected Products

Jenkins