Missing Permission Check in Jenkins Convertigo Mobile Platform Plugin
CVE-2022-34201

6.5MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
23 June 2022

Summary

The Jenkins Convertigo Mobile Platform Plugin before version 1.2 is susceptible to a missing permission check. Attackers with Overall/Read access can exploit this weakness to connect to URLs defined by them, potentially leading to unauthorized access or data exfiltration. Proper permission enforcement is essential to secure applications, particularly when integrating with external services.

Affected Version(s)

Jenkins Convertigo Mobile Platform Plugin <= 1.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.