cbcvebase.
CVE-2022-45383
published 2022-11-15

CVE-2022-45383: An incorrect permission check in Jenkins Support Core Plugin 1206.v14049fa_b_d860 and earlier allows attackers with Support/DownloadBundle permission to…

PriorityP434medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.65%
46.8th percentile
An incorrect permission check in Jenkins Support Core Plugin 1206.v14049fa_b_d860 and earlier allows attackers with Support/DownloadBundle permission to download a previously created support bundle containing information limited to users with Overall/Administer permission.

Affected

22 ranges
VendorProductVersion rangeFixed in
jenkinsassociated_files_plugin
jenkinsbart_plugin
jenkinscccc_plugin
jenkinscluster_statistics_plugin
jenkinsconfig_rotator_plugin
jenkinsdelete_log_plugin
jenkinsjapex_plugin
jenkinsjunit_plugin
jenkinsnaginator_plugin
jenkinsns-nd_integration_performance_publisher_plugin
jenkinspipeline_utility_steps_plugin
jenkinsregistry_notification_plugin
jenkinsreverse_proxy_auth_plugin
jenkinsscript_security_plugin
jenkinssourcemonitor_plugin
jenkinssupport_core< 1206.1208.v9b_7a_1d48db_0f1206.1208.v9b_7a_1d48db_0f
jenkinssupport_core_plugin
jenkinsurls_in_the_plugin
jenkinsviolations_plugin
jenkinsxml_linter_plugin
jenkinsxp-dev_plugin
jenkins_projectjenkins_support_core_pluginunspecified – 1206.v14049fa_b_d860
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.