Missing Permission Check in Jenkins Convertigo Mobile Platform Plugin
CVE-2022-34201
6.5MEDIUM
Key Information:
- Vendor
- Jenkins
- Vendor
- CVE Published:
- 23 June 2022
Summary
The Jenkins Convertigo Mobile Platform Plugin before version 1.2 is susceptible to a missing permission check. Attackers with Overall/Read access can exploit this weakness to connect to URLs defined by them, potentially leading to unauthorized access or data exfiltration. Proper permission enforcement is essential to secure applications, particularly when integrating with external services.
Affected Version(s)
Jenkins Convertigo Mobile Platform Plugin <= 1.1
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved