CVE-2022-34212: Medium severity vmware vrealize orchestrator vulnerability
Published Jun 22, 2022
·Updated
A missing permission check in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers with Overall/Read permission to send an HTTP POST request to an attacker-specified URL.
Affected Software
1 affected component
Jenkins Vrealize Orchestrator Jenkins<=3.0
Event History
Jun 22, 2022
CVE Published
via MITRE·02:41 PM
Data Sourced
via MITRE·02:41 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-34212?
CVE-2022-34212 is considered a medium severity vulnerability due to the potential for unauthorized HTTP POST requests.
2
How do I fix CVE-2022-34212?
To fix CVE-2022-34212, upgrade the Jenkins vRealize Orchestrator Plugin to version 3.1 or later.
3
Who is affected by CVE-2022-34212?
CVE-2022-34212 affects users of Jenkins with the vRealize Orchestrator Plugin version 3.0 and earlier.
4
What type of attack is possible with CVE-2022-34212?
CVE-2022-34212 allows attackers with Overall/Read permission to send malicious HTTP POST requests.
5
Is there a workaround for CVE-2022-34212?
Currently, there is no known workaround for CVE-2022-34212, so updating the plugin is essential.