VYPR
Moderate severityNVD Advisory· Published Jun 30, 2022· Updated Aug 3, 2024

CVE-2022-34782

CVE-2022-34782

Description

Jenkins requests-plugin Plugin 2.2.16 and earlier incorrectly allows users with Overall/Read permission to view pending requests.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Jenkins requests-plugin Plugin 2.2.16 and earlier incorrectly allows users with Overall/Read permission to view pending requests.

The Jenkins requests-plugin Plugin is designed to allow non-admin users to submit requests for operations like job deletion, renaming, or build unlocking. Administrators can then review and handle these pending requests. However, in version 2.2.16 and earlier, a missing permission check in the plugin exposes the list of pending requests to any authenticated user with the Overall/Read permission [1].

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.jenkins-ci.plugins:requestsMaven
< 2.2.172.2.17

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.