CVE-2022-28151
Description
Jenkins Job and Node ownership Plugin 0.13.0 and earlier lacks permission checks, allowing attackers with Item/Read to change job owners and permissions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Jenkins Job and Node ownership Plugin 0.13.0 and earlier lacks permission checks, allowing attackers with Item/Read to change job owners and permissions.
Vulnerability
Jenkins Job and Node ownership Plugin 0.13.0 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Item/Read permission to change the owners and item-specific permissions of a job. The affected plugin versions are all prior to the fix, which was not included in a released version as of the security advisory [1][2].
Exploitation
An attacker who has Item/Read permission on a Jenkins job (obtainable through the default permissions or by being granted that level of access) can send crafted HTTP requests to the plugin's endpoint to modify job ownership and item-specific permissions without needing any additional authorization. No special network position or user interaction is required beyond being an authenticated Jenkins user with Item/Read access [1][2].
Impact
Successful exploitation allows the attacker to change the owner of a job and adjust item-specific permissions (e.g., granting themselves Write or Configure access). This can lead to unauthorized manipulation of job configurations and potentially to further compromise of the Jenkins environment. The attacker may gain elevated privileges on jobs they previously had limited access to [1][2].
Mitigation
As of the security advisory published on 2022-03-29, no fixed version of the Jenkins Job and Node ownership Plugin was available. The advisory notes that the issue remains unresolved [1][2]. Users are advised to restrict Item/Read permission for untrusted users, monitor for any unexpected permission changes, and consider disabling the plugin if not required. No workaround other than access control restrictions has been documented.
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.synopsys.jenkinsci:ownershipMaven | <= 0.13.0 | — |
Affected products
2- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
5- github.com/advisories/GHSA-25f2-wgxj-ph29ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-28151ghsaADVISORY
- www.openwall.com/lists/oss-security/2022/03/29/1ghsamailing-listx_refsource_MLISTWEB
- www.jenkins.io/security/advisory/2022-03-29/mitrex_refsource_CONFIRM
- www.jenkins.io/security/advisory/2022-03-29/ghsaWEB
News mentions
1- Jenkins Security Advisory 2022-03-29Jenkins Security Advisories · Mar 29, 2022