Beveiligingsadvies

CVE-2022-34180

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-06-22 14:41:06
Laatst bijgewerkt 2024-08-03 08:16:17
Toegewezen door jenkins
CVSS-score geen score
Status PUBLISHED

Beschrijving

Jenkins Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in the HTTP endpoint it provides for "unprotected" status badge access, allowing attackers without any permissions to obtain the build status badge icon for any attacker-specified job and/or build.