CVE-2022-28147: Medium severity jenkins continuous integration with toad edge vulnerability
A missing permission check in Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier allows attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28147?
CVE-2022-28147 is classified as a medium-severity vulnerability due to the potential for unauthorized file path enumeration.
How do I fix CVE-2022-28147?
To fix CVE-2022-28147, upgrade the Jenkins Continuous Integration with Toad Edge Plugin to version 2.4 or later.
Who is affected by CVE-2022-28147?
Jenkins Continuous Integration with Toad Edge Plugin versions 2.3 and earlier are affected by CVE-2022-28147.
What type of attack is possible due to CVE-2022-28147?
CVE-2022-28147 allows attackers to check for the existence of specific file paths on the Jenkins controller.
What permissions are required to exploit CVE-2022-28147?
Attackers only need Overall/Read permission on Jenkins to exploit CVE-2022-28147.