Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.jenkins-ci.plugins/embeddable-build-status
  4. ›
  5. CVE-2022-34180

CVE-2022-34180: Missing Authorization

June 24, 2022 (updated July 5, 2022)

Jenkins Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in the HTTP endpoint it provides for “unprotected” status badge access, allowing attackers without any permissions to obtain the build status badge icon for any attacker-specified job and/or build.

References

  • github.com/advisories/GHSA-xxhf-xq6v-c8mj
  • nvd.nist.gov/vuln/detail/CVE-2022-34180
  • www.jenkins.io/security/advisory/2022-06-22/

Code Behaviors & Features

Detect and mitigate CVE-2022-34180 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.0.4

Fixed versions

  • 2.0.4

Solution

Upgrade to version 2.0.4 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-862: Missing Authorization

Source file

maven/org.jenkins-ci.plugins/embeddable-build-status/CVE-2022-34180.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:16:04 +0000.