Access Control Flaw in Rundeck Plugin for Jenkins
CVE-2022-41234
8.8HIGH
Summary
The Rundeck Plugin for Jenkins prior to version 3.6.12 has a significant access control vulnerability that exposes the /plugin/rundeck/webhook/ endpoint. This flaw allows users who possess Overall/Read permissions to trigger jobs that are intended to be securely activated via Rundeck. As a result, unauthorized users can execute sensitive jobs, which could lead to potential data breaches or disruptions in service. It is crucial for users to upgrade to the latest version to mitigate this risk and enhance overall security.
Affected Version(s)
Jenkins Rundeck Plugin <= 3.6.11
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved