Back to search
CVE-2022-34180
Published: Jun 22, 2022
Modified: Aug 3, 2024
PUBLISHED
Description
Jenkins Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in the HTTP endpoint it provides for "unprotected" status badge access, allowing attackers without any permissions to obtain the build status badge icon for any attacker-specified job and/or build.
| Vendor | Product | Versions |
|---|---|---|
Jenkins project | Jenkins Embeddable Build Status Plugin | affected unspecified - <= 2.0.3 |
References
https://www.jenkins.io/security/advisory/2022-06-22/#SECURITY-2794
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now