CVE-2022-45383 describes an incorrect permission check in Jenkins Support Core Plugin versions 1206.v14049fa_b_d860 and earlier. This vulnerability allows authenticated attackers with "Support/DownloadBundle" permission to download support bundles containing sensitive information typically restricted to administrators. Rated 6.5 MEDIUM, the attack requires low privileges and network access, potentially leading to high confidentiality impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1206.1208.v9b_7a_1d48db_0fCPE matchmatch criteria | cpe:2.3:a:jenkins:support_core:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.