Access Control Flaw in Rundeck Plugin for Jenkins
CVE-2022-41234
What is CVE-2022-41234?
The Rundeck Plugin for Jenkins prior to version 3.6.12 has a significant access control vulnerability that exposes the /plugin/rundeck/webhook/ endpoint. This flaw allows users who possess Overall/Read permissions to trigger jobs that are intended to be securely activated via Rundeck. As a result, unauthorized users can execute sensitive jobs, which could lead to potential data breaches or disruptions in service. It is crucial for users to upgrade to the latest version to mitigate this risk and enhance overall security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins Rundeck Plugin <= 3.6.11
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved