CVE-2022-30954: Medium severity jenkins vulnerability
Jenkins Blue Ocean Plugin 1.25.3 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified HTTP server.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-30954?
CVE-2022-30954 refers to a vulnerability in Jenkins Blue Ocean Plugin 1.25.3 and earlier that allows attackers with Overall/Read permission to connect to an attacker-specified HTTP server.
What is the severity of CVE-2022-30954?
CVE-2022-30954 has a severity rating of 6.5, which is considered medium.
How can I fix CVE-2022-30954?
To fix CVE-2022-30954, you should update your Jenkins Blue Ocean Plugin to version 1.25.4 or later.
Where can I find more information about CVE-2022-30954?
You can find more information about CVE-2022-30954 in the official Jenkins security advisory (https://www.jenkins.io/security/advisory/2022-05-17/#SECURITY-2502) and the Red Hat Security Errata (https://access.redhat.com/errata/RHSA-2023:0017).
What is the CWE ID for CVE-2022-30954?
The CWE ID for CVE-2022-30954 is 862.