Missing Permission Check in Jenkins Delete Log Plugin Exposes Build Logs to Deletion
CVE-2022-45394
4.3MEDIUM
Summary
A security issue in the Jenkins Delete Log Plugin, particularly in versions 1.0 and earlier, allows any user with Item/Read permission to delete build logs without proper authorization. This vulnerability can lead to unauthorized users manipulating sensitive build data, potentially obscuring important development history and hindering project accountability. Organizations utilizing this plugin are advised to review their permissions carefully and apply necessary updates to secure their CI/CD pipelines.
Affected Version(s)
Jenkins Delete log Plugin <= 1.0
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved