Permission Misconfiguration in Jenkins Job Import Plugin
CVE-2022-43413
4.3MEDIUM
What is CVE-2022-43413?
The Jenkins Job Import Plugin, versions 3.5 and earlier, lacks adequate permission checks for an HTTP endpoint. This oversight allows users with Overall/Read permission to list credential IDs stored within Jenkins, potentially compromising sensitive information. Proper controls should be implemented to prevent unauthorized access and ensure credential security.
Affected Version(s)
Jenkins Job Import Plugin <= 3.5