SB2022092313 - Missing Authorization in Jenkins extreme-feedback plugin



SB2022092313 - Missing Authorization in Jenkins extreme-feedback plugin

Published: September 23, 2022

Security Bulletin ID SB2022092313
Severity
Medium
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Missing Authorization (CVE-ID: CVE-2022-41242)

The vulnerability allows a remote attacker to bypass authorization checks.

The vulnerability exists due to the affected plugin does not perform a permission check in an HTTP endpoint. A remote user can discover information about job names attached to lamps, discover MAC and IP addresses of existing lamps and rename lamps.


Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.