Jenkins Recipe Plugin Vulnerability Exposes Sensitive Data to Unauthorized Access
CVE-2022-34794
6.5MEDIUM
What is CVE-2022-34794?
The Jenkins Recipe Plugin, specifically in version 1.2 and earlier, suffers from a critical oversight where missing permission checks allow users with Overall/Read access to send HTTP requests to any specified URL. This flaw leads to the ability to parse the response as XML, potentially exposing sensitive information and enabling further attacks on the system.
Affected Version(s)
Jenkins Recipe Plugin <= 1.2