PT-2022-22366 · Jenkins · Jenkins Request Rename/Delete Plugin+1

S0Nnguy3N

+1

·

Published

2022-06-30

·

Updated

2023-11-22

·

CVE-2022-34814

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Request Rename Or Delete Plugin versions 1.1.0 and earlier
Description The issue arises from an incorrect permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to view an administrative configuration page that lists pending requests.
Recommendations For Jenkins Request Rename Or Delete Plugin versions 1.1.0 and earlier, consider restricting access to the administrative configuration page until a patch is available. As a temporary workaround, review and limit the Overall/Read permissions to minimize the risk of exploitation.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-34814
GHSA-QHMJ-29VH-8MJM

Affected Products

Jenkins
Jenkins Request Rename/Delete Plugin