cbcvebase.
CVE-2022-41228
published 2022-09-21

CVE-2022-41228: A missing permission check in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers with Overall/Read permissions to…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
A missing permission check in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers with Overall/Read permissions to connect to an attacker-specified webserver using attacker-specified credentials.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
inteloptimization_for_tensorflow>= 0 < 2.6.42.6.4
inteloptimization_for_tensorflow>= 2.7.0 < 2.7.22.7.2
inteloptimization_for_tensorflow>= 2.8.0 < 2.8.12.8.1
jenkinsanchore_container_image_scanner_plugin
jenkinsapprenda_plugin
jenkinsbigpanda_notifier_plugin
jenkinsbmc_ami_common_configuration_plugin
jenkinscons3rt_plugin
jenkinsdotci_plugin
jenkinsjenkins_core
jenkinsjenkins_weekly
jenkinslack_of_authentication_mechanism_in_dotci_plugin
jenkinsns-nd_integration_performance_publisher< 4.8.0.1304.8.0.130
jenkinsns-nd_integration_performance_publisher_plugin
jenkinsrqm_plugin
jenkinsrundeck_plugin
jenkinsscm_httpclient_plugin
jenkinssecurity_inspector_plugin
jenkinssmalltest_plugin
jenkinsthis_could_create_confusion_in_users_of_the_plugin
jenkinsurls_of_jenkins_servers_that_the_plugin
jenkinsview26_test-reporting_plugin
jenkinswalti_plugin
jenkinswildfly_deployer_plugin
jenkinsworksoft_execution_manager_plugin

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ghsa7.8HIGH