CVE-2022-34180: High severity jenkins embeddable build status vulnerability

Published Jun 22, 2022
·
Updated

Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in the HTTP endpoint it provides for \"unprotected\" status badge access.

This allows attackers without any permissions to obtain the build status badge icon for any attacker-specified job and/or build.

Embeddable Build Status Plugin 2.0.4 requires ViewStatus permission to obtain the build status badge icon.

Other sources

Jenkins Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in the HTTP endpoint it provides for "unprotected" status badge access, allowing attackers without any permissions to obtain the build status badge icon for any attacker-specified job and/or build.

Affected Software

2 affected componentsFixes available
maven/org.jenkins-ci.plugins:embeddable-build-status<2.0.4
2.0.4
Jenkins Embeddable Build Status Jenkins<=2.0.3

Event History

Jun 22, 2022
CVE Published
via MITRE·02:41 PM
Data Sourced
via MITRE·02:41 PM
Description
Jun 24, 2022
Advisory Published
12:00 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2022-34180?

CVE-2022-34180 has a medium severity rating due to improper permission checks that could allow unauthorized access to build status badges.

2

How do I fix CVE-2022-34180?

To fix CVE-2022-34180, update the Embeddable Build Status Plugin to version 2.0.4 or later.

3

Which versions of the Embeddable Build Status Plugin are affected by CVE-2022-34180?

CVE-2022-34180 affects versions 2.0.3 and earlier of the Embeddable Build Status Plugin.

4

What is the impact of CVE-2022-34180?

The impact of CVE-2022-34180 is that attackers can view build status badges without required permissions, potentially leading to information leaks.

5

Is authentication required to exploit CVE-2022-34180?

No, authentication is not required to exploit CVE-2022-34180, making it a significant security concern.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203