PT-2022-4009 · Jenkins · Jenkins Lucene-Search Plugin+1

Jeff Thompson

·

Published

2022-07-27

·

Updated

2023-11-22

·

CVE-2022-36910

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Lucene-Search Plugin versions 370.v62a5f618cd3a and earlier
Description The issue is related to insufficient authorization procedures in the Jenkins Lucene-Search Plugin, allowing attackers with Overall/Read permission to access protected information. Specifically, the plugin does not perform permission checks in several HTTP endpoints, enabling attackers to reindex the database and obtain information about jobs that would otherwise be inaccessible to them.
Recommendations For Jenkins Lucene-Search Plugin versions 370.v62a5f618cd3a and earlier, consider disabling access to the vulnerable HTTP endpoints until a patch is available. Restrict access to the plugin's functionality to minimize the risk of exploitation, especially for users with Overall/Read permission.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04842
CVE-2022-36910
GHSA-M8W5-VWQ3-GP8F

Affected Products

Jenkins
Jenkins Lucene-Search Plugin