PT-2022-27491 · Jenkins · Jenkins Xp-Dev Plugin+1

Kevin Guerroudj

·

Published

2022-11-15

·

Updated

2023-11-01

·

CVE-2022-45389

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins XP-Dev Plugin version 1.0 and earlier
Description A missing permission check in the Jenkins XP-Dev Plugin allows unauthenticated attackers to trigger builds of jobs corresponding to an attacker-specified repository.
Recommendations For Jenkins XP-Dev Plugin version 1.0 and earlier, update to a version that includes the necessary permission checks to prevent unauthenticated access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-45389
GHSA-X9WP-GFRR-P5RP

Affected Products

Jenkins
Jenkins Xp-Dev Plugin