CVE-2022-2062
JavaScript vulnerability analysis and mitigation

Overview

The Job and Node ownership Plugin for Jenkins version 0.13.0 and earlier contains multiple security vulnerabilities identified as SECURITY-2062. The vulnerabilities include a Cross-Site Request Forgery (CSRF) vulnerability (CVE-2022-28150) and a missing permission check (CVE-2022-28151) that affect the plugin's HTTP endpoints (Jenkins Advisory).

Technical details

The vulnerability allows attackers with Item/Read permission to change the owners and item-specific permissions of a job due to missing permission checks in several HTTP endpoints. Additionally, these endpoints do not require POST requests, resulting in a cross-site request forgery (CSRF) vulnerability. The CVSS severity is rated as Medium. The CSRF vulnerability is only exploitable in Jenkins 2.286 and earlier, LTS 2.277.1 and earlier (Jenkins Advisory).

Impact

Successful exploitation of these vulnerabilities could allow attackers to modify job ownership settings and item-specific permissions without proper authorization. This could lead to unauthorized access control changes and potential privilege escalation within affected Jenkins installations (Jenkins Advisory).

Exploitability

The vulnerabilities require an attacker to have Item/Read permission in the Jenkins instance. The CSRF vulnerability can be exploited through specially crafted web pages that make unauthorized requests to the affected endpoints when viewed by authenticated users (Jenkins Advisory).

Mitigation and workarounds

As of the advisory publication date, there is no fix available for these vulnerabilities in the Job and Node ownership Plugin. Users should consider implementing additional access controls and monitoring of job ownership changes until a patch becomes available (Jenkins Advisory).

Additional resources


SourceThis report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-48170CRITICAL9.1
  • JavaScript logoJavaScript
  • scim-patch
NoYesAug 07, 2026
CVE-2026-48007HIGH8.6
  • JavaScript logoJavaScript
  • @element-hq/element-call-embedded
NoYesAug 07, 2026
CVE-2026-69207MEDIUM5.3
  • JavaScript logoJavaScript
  • gemini-cli
NoYesAug 07, 2026
CVE-2026-71850MEDIUM4.8
  • JavaScript logoJavaScript
  • hono
NoYesAug 07, 2026
CVE-2026-71849LOW3.7
  • JavaScript logoJavaScript
  • hono
NoYesAug 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management