PT-2022-22048 · Jenkins · Jenkins Embeddable Build Status Plugin+1

Published

2022-06-22

·

Updated

2023-11-03

·

CVE-2022-34180

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Embeddable Build Status Plugin versions 2.0.3 and earlier
Description The issue concerns the incorrect performance of the ViewStatus permission check in the HTTP endpoint provided for "unprotected" status badge access. This allows attackers without any permissions to obtain the build status badge icon for any attacker-specified job and/or build.
Recommendations For Jenkins Embeddable Build Status Plugin versions 2.0.3 and earlier, update to version 2.0.4 or later, which requires ViewStatus permission to obtain the build status badge icon. As a temporary workaround, consider restricting access to the HTTP endpoint for "unprotected" status badge access until a patch is available.

Fix

Incorrect Authorization

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-34180
GHSA-XXHF-XQ6V-C8MJ

Affected Products

Jenkins
Jenkins Embeddable Build Status Plugin