CVE-2022-34201: Medium severity jenkins convertigo mobile platform vulnerability
Published Jun 22, 2022
·Updated
A missing permission check in Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.
Affected Software
1 affected component
Jenkins Convertigo Mobile Platform Jenkins<=1.1
Event History
Jun 22, 2022
CVE Published
via MITRE·02:41 PM
Data Sourced
via MITRE·02:41 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-34201?
CVE-2022-34201 has a medium severity rating due to the potential for unauthorized access to attacker-specified URLs.
2
How do I fix CVE-2022-34201?
To fix CVE-2022-34201, update Jenkins Convertigo Mobile Platform Plugin to version 1.2 or later.
3
Who is affected by CVE-2022-34201?
Users of Jenkins Convertigo Mobile Platform Plugin version 1.1 and earlier are affected by CVE-2022-34201.
4
What causes CVE-2022-34201?
CVE-2022-34201 is caused by a missing permission check that allows Access/Overall permissions to connect to arbitrary URLs.
5
What can attackers achieve with CVE-2022-34201?
Attackers can exploit CVE-2022-34201 to connect to an attacker-specified URL if they have Overall/Read permission.