Lucene search

K
cve[email protected]CVE-2022-36891
HistoryJul 27, 2022 - 3:15 p.m.

CVE-2022-36891

2022-07-2715:15:09
CWE-862
web.nvd.nist.gov
44
4
jenkins
deployer framework
plugin
cve-2022-36891
security
vulnerability
nvd

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

4.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.3%

A missing permission check in Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier allows attackers with Item/Read permission but without Deploy Now/Deploy permission to read deployment logs.

Affected configurations

NVD
Node
jenkinsdeployer_frameworkRange85.v1d1888e8c021jenkins

CNA Affected

[
  {
    "product": "Jenkins Deployer Framework Plugin",
    "vendor": "Jenkins project",
    "versions": [
      {
        "lessThanOrEqual": "85.v1d1888e8c021",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "status": "unaffected",
        "version": "1.3.1"
      }
    ]
  }
]

Social References

More

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

4.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.3%