
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-36909 is a security vulnerability in the OpenShift Deployer Plugin for Jenkins, discovered and disclosed on July 27, 2022. The vulnerability affects OpenShift Deployer Plugin versions 1.2.0 and earlier, and is categorized with a Medium severity (CVSS) rating (Jenkins Advisory).
The vulnerability stems from a missing permission check in methods implementing form validation in the OpenShift Deployer Plugin. This security flaw is part of a broader issue tracked as SECURITY-1375 (2) that also includes a related CSRF vulnerability (CVE-2022-36908). The vulnerability specifically relates to the plugin's form validation methods that handle file path verification and SSH key file uploads (Jenkins Advisory).
The vulnerability allows attackers with Overall/Read permission to check for the existence of attacker-specified file paths on the Jenkins controller file system and to upload SSH key files from the Jenkins controller file system to attacker-specified URLs. This creates a potential security risk for unauthorized file system access and data exfiltration (Jenkins Advisory).
As of the advisory's publication date, no official fix was available for this vulnerability in the OpenShift Deployer Plugin. The plugin version 1.2.0 and earlier remain vulnerable, and no updated version has been released to address this security issue (Jenkins Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."