PT-2022-22046 · Jenkins · Jenkins Embeddable Build Status Plugin+1

Published

2022-06-22

·

Updated

2023-11-03

·

CVE-2022-34179

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Embeddable Build Status Plugin versions 2.0.3 and earlier
Description The issue allows attackers without Overall/Read permission to specify paths to other SVG images on the Jenkins controller file system by exploiting a relative path traversal vulnerability. This is possible because the style query parameter, used to choose a different SVG image style, does not restrict possible values.
Recommendations For Jenkins Embeddable Build Status Plugin versions 2.0.3 and earlier, update to version 2.0.4 or later, which restricts the style query parameter to one of the three legal values.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-34179
GHSA-93MX-2VF9-28C4

Affected Products

Jenkins
Jenkins Embeddable Build Status Plugin