PT-2022-4025 · Jenkins · Jenkins Openshift Deployer Plugin+1
Daniel Beck
·
Published
2022-07-27
·
Updated
2023-11-02
·
CVE-2022-36907
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins OpenShift Deployer Plugin versions 1.2.0 and earlier
Description
The issue is related to a missing permission check in the plugin, which can be exploited by attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified
username and password. This can allow unauthorized access to protected information.Recommendations
For Jenkins OpenShift Deployer Plugin versions 1.2.0 and earlier, consider disabling the plugin until a patch is available to prevent attackers from exploiting the missing permission check.
As a temporary workaround, restrict access to the plugin's functionality to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Openshift Deployer Plugin