PT-2022-4025 · Jenkins · Jenkins Openshift Deployer Plugin+1

Daniel Beck

·

Published

2022-07-27

·

Updated

2023-11-02

·

CVE-2022-36907

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Jenkins OpenShift Deployer Plugin versions 1.2.0 and earlier
Description The issue is related to a missing permission check in the plugin, which can be exploited by attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified username and password. This can allow unauthorized access to protected information.
Recommendations For Jenkins OpenShift Deployer Plugin versions 1.2.0 and earlier, consider disabling the plugin until a patch is available to prevent attackers from exploiting the missing permission check. As a temporary workaround, restrict access to the plugin's functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2022-04858
CVE-2022-36907
GHSA-JVJH-9R4Q-8Q5Q

Affected Products

Jenkins
Jenkins Openshift Deployer Plugin