Missing Permission Check in Jenkins Convertigo Mobile Platform Plugin
CVE-2022-34201

6.5MEDIUM

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
23 June 2022

What is CVE-2022-34201?

The Jenkins Convertigo Mobile Platform Plugin before version 1.2 is susceptible to a missing permission check. Attackers with Overall/Read access can exploit this weakness to connect to URLs defined by them, potentially leading to unauthorized access or data exfiltration. Proper permission enforcement is essential to secure applications, particularly when integrating with external services.

Affected Version(s)

Jenkins Convertigo Mobile Platform Plugin <= 1.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.