PT-2022-6109 · Jenkins · Jenkins Tuleap Git Branch Source Plugin+1

Kevin Guerroudj

·

Published

2022-10-19

·

Updated

2025-05-08

·

CVE-2022-43421

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Tuleap Git Branch Source Plugin versions 3.2.4 and earlier
Description The issue is related to a missing permission check in the Jenkins Tuleap Git Branch Source Plugin, allowing unauthenticated attackers to trigger Tuleap projects. This can be achieved when the configured repository matches the attacker-specified value. The vulnerability is also associated with insufficient authorization procedures when handling the /tuleap-hook/ endpoint, potentially allowing remote attackers to gain unauthorized access to protected information.
Recommendations For Jenkins Tuleap Git Branch Source Plugin versions 3.2.4 and earlier, consider updating to version 3.2.5 or later, which requires a token to access the webhook endpoint, thereby mitigating the risk of unauthorized access. As a temporary workaround, consider restricting access to the /tuleap-hook/ endpoint to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2023-00049
CVE-2022-43421
GHSA-73V5-W6FG-2M44

Affected Products

Jenkins
Jenkins Tuleap Git Branch Source Plugin