SB2022092313 - Missing Authorization in Jenkins extreme-feedback plugin
Published: September 23, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Missing Authorization (CVE-ID: CVE-2022-41242)
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to the affected plugin does not perform a permission check in an HTTP endpoint. A remote user can discover information about job names attached to lamps, discover MAC and IP addresses of existing lamps and rename lamps.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.