PT-2022-6107 · Jenkins · Jenkins Extreme-Feedback Plugin+1
Published
2022-09-21
·
Updated
2025-05-28
·
CVE-2022-41242
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins extreme-feedback Plugin versions 1.7 and earlier
Description
The issue is related to a missing permission check in the Jenkins extreme-feedback Plugin, allowing attackers with Overall/Read permission to access sensitive information. This includes discovering job names attached to lamps, MAC and IP addresses of existing lamps, and renaming lamps. The exploitation of this issue can impact the confidentiality and integrity of protected information.
Recommendations
For Jenkins extreme-feedback Plugin versions 1.7 and earlier, as a temporary workaround, consider restricting access to the plugin's HTTP endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Extreme-Feedback Plugin