PT-2022-22348 · Jenkins · Jenkins Deployment Dashboard Plugin+1

Kevin Guerroudj

·

Published

2022-06-30

·

Updated

2023-11-22

·

CVE-2022-34796

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Deployment Dashboard Plugin versions 1.0.10 and earlier
Description A missing permission check in the plugin allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. This issue affects several HTTP endpoints, which do not perform permission checks. The enumerated credentials IDs can be used as part of an attack to capture the credentials using another vulnerability.
Recommendations For Jenkins Deployment Dashboard Plugin versions 1.0.10 and earlier, as a temporary workaround, consider restricting access to the affected HTTP endpoints until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2022-34796
GHSA-5MXG-P5QH-2GCH

Affected Products

Jenkins
Jenkins Deployment Dashboard Plugin