CVE-2022-34208 is a medium-severity vulnerability affecting Jenkins Beaker builder Plugin versions 1.10 and earlier, stemming from a missing permission check. This flaw allows authenticated attackers with "Overall/Read" permissions to force the Jenkins instance to connect to an attacker-controlled URL. While the CVSS score is 4.3 (medium) due to low impact (no confidentiality, integrity, or availability compromise), there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.10CPE matchmatch criteria | cpe:2.3:a:jenkins:beaker_builder:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.