Unauthorized Access in Jenkins Request Rename Or Delete Plugin
CVE-2022-34814
4.3MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 30 June 2022
What is CVE-2022-34814?
The Request Rename Or Delete Plugin for Jenkins versions 1.1.0 and earlier contains a vulnerability where it fails to adequately validate permissions for an HTTP endpoint. This oversight permits users with Overall/Read access to access restricted administrative configuration pages, potentially compromising sensitive information about pending requests.
Affected Version(s)
Jenkins Request Rename Or Delete Plugin <= 1.1.0