CVE-2022-34785: Medium severity jenkins build-metrics vulnerability
Jenkins build-metrics Plugin 1.3 and earlier does not perform a permission check in multiple HTTP endpoints.
This allows attackers with Overall/Read permission to obtain information about jobs otherwise inaccessible to them.
As of publication of this advisory, there is no fix.
Other sources
Jenkins build-metrics Plugin 1.3 and earlier does not perform permission checks in multiple HTTP endpoints, allowing attackers with Overall/Read permission to obtain information about jobs otherwise inaccessible to them.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-34785?
CVE-2022-34785 has a high severity rating due to unauthorized access to sensitive job information.
How do I fix CVE-2022-34785?
As of now, there is no official fix for CVE-2022-34785, and users should monitor for updates.
Who is affected by CVE-2022-34785?
CVE-2022-34785 affects users of Jenkins build-metrics Plugin versions 1.3 and earlier.
What type of vulnerability is CVE-2022-34785?
CVE-2022-34785 is a permission vulnerability that allows unauthorized information access.
What are the potential impacts of CVE-2022-34785?
CVE-2022-34785 can lead to exposure of sensitive job information to users with Overall/Read permission.