PT-2022-4009 · Jenkins · Jenkins Lucene-Search Plugin+1
Jeff Thompson
·
Published
2022-07-27
·
Updated
2023-11-22
·
CVE-2022-36910
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Lucene-Search Plugin versions 370.v62a5f618cd3a and earlier
Description
The issue is related to insufficient authorization procedures in the Jenkins Lucene-Search Plugin, allowing attackers with Overall/Read permission to access protected information. Specifically, the plugin does not perform permission checks in several HTTP endpoints, enabling attackers to reindex the database and obtain information about jobs that would otherwise be inaccessible to them.
Recommendations
For Jenkins Lucene-Search Plugin versions 370.v62a5f618cd3a and earlier, consider disabling access to the vulnerable HTTP endpoints until a patch is available. Restrict access to the plugin's functionality to minimize the risk of exploitation, especially for users with Overall/Read permission.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Lucene-Search Plugin