Missing Permission Check in Jenkins Compuware Xpediter Code Coverage Plugin
CVE-2022-36897
4.3MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 27 July 2022
What is CVE-2022-36897?
The Compuware Xpediter Code Coverage Plugin for Jenkins has a critical oversight where a missing permission check allows users with Overall/Read permission to enumerate detailed configurations. This vulnerability could lead to the exposure of sensitive information, including the hosts and ports of Compuware configurations, as well as the credentials IDs stored within Jenkins, posing a significant risk to the security of sensitive data.
Affected Version(s)
Jenkins Compuware Xpediter Code Coverage Plugin <= 1.0.7