CVE-2022-34785
30.06.2022, 18:15
Jenkins build-metrics Plugin 1.3 and earlier does not perform permission checks in multiple HTTP endpoints, allowing attackers with Overall/Read permission to obtain information about jobs otherwise inaccessible to them.Enginsight
Vendor | Product | Version |
---|---|---|
jenkins | build-metrics | 𝑥 ≤ 1.3 |
𝑥
= Vulnerable software versions