Description
Jenkins build-metrics Plugin 1.3 and earlier does not perform permission checks in multiple HTTP endpoints, allowing attackers with Overall/Read permission to obtain information about jobs otherwise inaccessible to them.
Remediation
References
https://www.jenkins.io/security/advisory/2022-06-30/#SECURITY-2643
Related Vulnerabilities
CVE-2022-43421 Vulnerability in maven package org.jenkins-ci.plugins:tuleap-git-branch-source
CVE-2019-10385 Vulnerability in maven package org.jenkins-ci.plugins:eggplant-plugin
CVE-2011-4838 Vulnerability in maven package org.jruby:jruby
CVE-2013-6448 Vulnerability in maven package org.jboss.seam:jboss-seam-remoting
CVE-2009-2625 Vulnerability in maven package xerces:xercesimpl