CVE-2022-34794: Medium severity jenkins vulnerability
Missing permission checks in Jenkins Recipe Plugin 1.2 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacker-specified URL and parse the response as XML.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-34794?
CVE-2022-34794 is a vulnerability in the Jenkins Recipe Plugin version 1.2 and earlier that allows attackers with Overall/Read permission to send an HTTP request to an attacker-specified URL and parse the response as XML.
How severe is CVE-2022-34794?
CVE-2022-34794 has a severity rating of 6.5 out of 10, which is considered medium severity.
Which software is affected by CVE-2022-34794?
Jenkins Recipe Plugin version 1.2 and earlier is affected by CVE-2022-34794.
How can I fix CVE-2022-34794?
To fix CVE-2022-34794, update Jenkins Recipe Plugin to a version later than 1.2.
Where can I find more information about CVE-2022-34794?
You can find more information about CVE-2022-34794 in the official Jenkins security advisory: [link](https://www.jenkins.io/security/advisory/2022-06-30/#SECURITY-2000)