Description
Jenkins 2.335 through 2.355 (both inclusive) allows attackers in some cases to bypass a protection mechanism, thereby directly accessing some view fragments containing sensitive information, bypassing any permission checks in the corresponding view.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6103 | Jenkins 2.335 through 2.355 (both inclusive) allows attackers in some cases to bypass a protection mechanism, thereby directly accessing some view fragments containing sensitive information, bypassing any permission checks in the corresponding view. |
Github GHSA |
GHSA-p3rc-946h-8cf5 | Unauthorized view fragment access in Jenkins |
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-03T08:16:17.220Z
Reserved: 2022-06-21T00:00:00.000Z
Link: CVE-2022-34175
No data.
Status : Modified
Published: 2022-06-23T17:15:15.563
Modified: 2024-11-21T07:09:00.333
Link: CVE-2022-34175
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA