Improper Access Control in Jenkins Release Helper Plugin
CVE-2022-27215
4.3MEDIUM
Summary
The Jenkins Release Helper Plugin does not sufficiently enforce permission checks, which allows users with Overall/Read permissions to connect to potentially malicious URLs with attacker-specified credentials. This vulnerability could lead to unauthorized actions and data exposure, as attackers could leverage this access to manipulate system behavior or extract sensitive information from the target environment.
Affected Version(s)
Jenkins Release Helper Plugin <= 1.3.3
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved