CVE-2022-36912: Medium severity openstack heat vulnerability
Published Jul 27, 2022
·Updated
A missing permission check in Jenkins Openstack Heat Plugin 1.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.
Affected Software
1 affected component
Jenkins Openstack Heat Jenkins<=1.5
Event History
Jul 27, 2022
CVE Published
via MITRE·02:27 PM
Data Sourced
via MITRE·02:27 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-36912?
CVE-2022-36912 has a medium severity level due to its potential for unauthorized access to URLs.
2
How do I fix CVE-2022-36912?
To fix CVE-2022-36912, update the Jenkins Openstack Heat Plugin to version 1.6 or later.
3
Who is affected by CVE-2022-36912?
CVE-2022-36912 affects users of the Jenkins Openstack Heat Plugin version 1.5 and earlier.
4
What conditions allow exploitation of CVE-2022-36912?
CVE-2022-36912 can be exploited by attackers with Overall/Read permission in Jenkins.
5
What functionality is impacted by CVE-2022-36912?
CVE-2022-36912 allows attackers to connect to a specified URL, bypassing intended permission checks.