Description
Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to reindex the database and to obtain information about jobs otherwise inaccessible to them.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6375 | Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to reindex the database and to obtain information about jobs otherwise inaccessible to them. |
Github GHSA |
GHSA-m8w5-vwq3-gp8f | Lucene-Search Plugin does not perform permission checks in several HTTP endpoints |
References
History
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-03T10:14:29.472Z
Reserved: 2022-07-27T00:00:00.000Z
Link: CVE-2022-36910
No data.
Status : Modified
Published: 2022-07-27T15:15:10.277
Modified: 2024-11-21T07:14:03.820
Link: CVE-2022-36910
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA