CVE-2022-34798: Medium severity jenkins deployment dashboard plugin vulnerability
Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified HTTP URL using attacker-specified credentials.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Jenkins plugin?
The vulnerability ID of this Jenkins plugin is CVE-2022-34798.
What is the title of the vulnerability?
The title of the vulnerability is 'Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not perform a permission check in several HTTP endpoints'.
What is the impact of this vulnerability?
This vulnerability allows attackers with Overall/Read permission to connect to an attacker-specified HTTP URL using attacker-specified credentials.
How severe is this vulnerability?
This vulnerability has a severity rating of medium (CVSS score: 4.3).
How can I fix this vulnerability?
To fix this vulnerability, update the Jenkins Deployment Dashboard Plugin to version 1.0.11 or later.