CVE-2022-34785
EUVD-2022-640630.06.2022, 18:15
Jenkins build-metrics Plugin 1.3 and earlier does not perform permission checks in multiple HTTP endpoints, allowing attackers with Overall/Read permission to obtain information about jobs otherwise inaccessible to them.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| jenkins | build-metrics | 𝑥 ≤ 1.3 |
𝑥
= Vulnerable software versions