First published: Tue Nov 15 2022(Updated: )
A missing permission check in Jenkins Cluster Statistics Plugin 0.4.6 and earlier allows attackers to delete recorded Jenkins Cluster Statistics.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Cluster Statistics | <=0.4.6 | |
maven/org.zeroturnaround:cluster-stats | <=0.4.6 | |
<=0.4.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-45399 is classified as a medium severity vulnerability due to the potential impact on Jenkins Cluster Statistics.
To fix CVE-2022-45399, upgrade to Cluster Statistics Plugin version 0.4.7 or later.
CVE-2022-45399 is caused by a missing permission check in the Jenkins Cluster Statistics Plugin.
Users of Jenkins Cluster Statistics Plugin version 0.4.6 and earlier are affected by CVE-2022-45399.
Exploiting CVE-2022-45399 allows attackers to delete recorded Jenkins Cluster Statistics due to insufficient permissions.