CVE-2022-34180

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-34180
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-34180.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-34180
Aliases
Published
2022-06-23T17:15:15Z
Modified
2024-09-03T04:17:04.753125Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Jenkins Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in the HTTP endpoint it provides for "unprotected" status badge access, allowing attackers without any permissions to obtain the build status badge icon for any attacker-specified job and/or build.

References

Affected packages

Git / github.com/jenkinsci/embeddable-build-status-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/embeddable-build-status-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

embeddable-build-status-1.*

embeddable-build-status-1.0
embeddable-build-status-1.1
embeddable-build-status-1.2
embeddable-build-status-1.3
embeddable-build-status-1.4
embeddable-build-status-1.5
embeddable-build-status-1.6
embeddable-build-status-1.7
embeddable-build-status-1.8
embeddable-build-status-1.9

embeddable-build-status-2.*

embeddable-build-status-2.0
embeddable-build-status-2.0-beta1
embeddable-build-status-2.0-beta2
embeddable-build-status-2.0.1
embeddable-build-status-2.0.2
embeddable-build-status-2.0.3