Missing Permission Check in Jenkins Delete Log Plugin Exposes Build Logs to Deletion
CVE-2022-45394
4.3MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 15 November 2022
What is CVE-2022-45394?
A security issue in the Jenkins Delete Log Plugin, particularly in versions 1.0 and earlier, allows any user with Item/Read permission to delete build logs without proper authorization. This vulnerability can lead to unauthorized users manipulating sensitive build data, potentially obscuring important development history and hindering project accountability. Organizations utilizing this plugin are advised to review their permissions carefully and apply necessary updates to secure their CI/CD pipelines.
Affected Version(s)
Jenkins Delete log Plugin <= 1.0