First published: Thu Jun 30 2022(Updated: )
An incorrect permission check in Jenkins requests-plugin Plugin 2.2.16 and earlier allows attackers with Overall/Read permission to view the list of pending requests.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Requests | <=2.2.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Jenkins requests-plugin Plugin vulnerability is CVE-2022-34782.
The severity of CVE-2022-34782 is medium with a CVSS score of 4.3.
CVE-2022-34782 allows attackers with Overall/Read permission to view the list of pending requests in Jenkins requests-plugin Plugin 2.2.16 and earlier.
The affected software for CVE-2022-34782 is Jenkins requests-plugin Plugin version 2.2.16 and earlier.
Yes, a fix for CVE-2022-34782 is available. Users should update to Jenkins requests-plugin Plugin version 2.2.17 or later.