Junglewise Threat Intelligence

CVE-2022-36891: Jenkins Deployer Framework Plugin allows attackers with Item/Read permission to read deployment logs

CVE-2022-36891 · Severity: low · CVSS 3.1 · Published 2022-07-28

Technologies: org.jenkins-ci.plugins:deployer-framework (Maven). Vendors: Maven.

Executive brief

Jenkins Deployer Framework Plugin allows attackers with Item/Read permission to read deployment logs

Affected products

  • Maven org.jenkins-ci.plugins:deployer-framework

Related threats