Missing Permission Check in Jenkins Convertigo Mobile Platform Plugin
CVE-2022-34201
6.5MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 23 June 2022
What is CVE-2022-34201?
The Jenkins Convertigo Mobile Platform Plugin before version 1.2 is susceptible to a missing permission check. Attackers with Overall/Read access can exploit this weakness to connect to URLs defined by them, potentially leading to unauthorized access or data exfiltration. Proper permission enforcement is essential to secure applications, particularly when integrating with external services.
Affected Version(s)
Jenkins Convertigo Mobile Platform Plugin <= 1.1