CVE-2022-34180: High severity jenkins embeddable build status vulnerability
Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in the HTTP endpoint it provides for \"unprotected\" status badge access.
This allows attackers without any permissions to obtain the build status badge icon for any attacker-specified job and/or build.
Embeddable Build Status Plugin 2.0.4 requires ViewStatus permission to obtain the build status badge icon.
Other sources
Jenkins Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in the HTTP endpoint it provides for "unprotected" status badge access, allowing attackers without any permissions to obtain the build status badge icon for any attacker-specified job and/or build.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-34180?
CVE-2022-34180 has a medium severity rating due to improper permission checks that could allow unauthorized access to build status badges.
How do I fix CVE-2022-34180?
To fix CVE-2022-34180, update the Embeddable Build Status Plugin to version 2.0.4 or later.
Which versions of the Embeddable Build Status Plugin are affected by CVE-2022-34180?
CVE-2022-34180 affects versions 2.0.3 and earlier of the Embeddable Build Status Plugin.
What is the impact of CVE-2022-34180?
The impact of CVE-2022-34180 is that attackers can view build status badges without required permissions, potentially leading to information leaks.
Is authentication required to exploit CVE-2022-34180?
No, authentication is not required to exploit CVE-2022-34180, making it a significant security concern.