CVE-2022-41230

Description

Jenkins Build-Publisher Plugin 1.22 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to obtain names and URLs of Jenkins servers that the plugin is configured to publish builds to, as well as builds pending for publication to those Jenkins servers.

Risk Information

Base Score
4.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.252

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2022-41232,CVE-2022-41231,CVE-2022-41230 are affected in Jenkins - build-publisher 1.22Windows
Vulnerabilities CVE-2022-41232,CVE-2022-41231,CVE-2022-41230 are affected in Jenkins - build-publisher for Linux 1.22Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234