CVE-2022-34179: Path Traversal
Published Jun 22, 2022
·Updated
Jenkins Embeddable Build Status Plugin 2.0.3 and earlier allows specifying a style query parameter that is used to choose a different SVG image style without restricting possible values, resulting in a relative path traversal vulnerability that allows attackers without Overall/Read permission to specify paths to other SVG images on the Jenkins controller file system.
Affected Software
1 affected component
Jenkins Embeddable Build Status Jenkins<=2.0.3
Event History
Jun 22, 2022
CVE Published
via MITRE·02:41 PM
Data Sourced
via MITRE·02:41 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-34179?
CVE-2022-34179 is classified as a medium severity vulnerability.
2
How do I fix CVE-2022-34179?
To fix CVE-2022-34179, update the Jenkins Embeddable Build Status Plugin to version 2.0.4 or later.
3
What does CVE-2022-34179 affect?
CVE-2022-34179 affects Jenkins Embeddable Build Status Plugin versions 2.0.3 and earlier.
4
What type of vulnerability is CVE-2022-34179?
CVE-2022-34179 is a relative path traversal vulnerability.
5
Who can exploit CVE-2022-34179?
Attackers without Overall/Read permission can exploit CVE-2022-34179.