VYPR
Moderate severityNVD Advisory· Published Jun 30, 2022· Updated Aug 3, 2024

CVE-2022-34811

CVE-2022-34811

Description

Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier lacks a permission check, allowing attackers with Overall/Read permission to access the XPath Configuration Viewer page.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier lacks a permission check, allowing attackers with Overall/Read permission to access the XPath Configuration Viewer page.

The Jenkins XPath Configuration Viewer Plugin up to version 1.1.1 fails to perform a proper permission check when rendering the XPath Configuration Viewer page. This missing authorization allows any user with the Overall/Read permission to view the page, which should require a higher privilege level such as Overall/Administer [1].

An attacker who has already obtained Overall/Read access to a Jenkins instance—a relatively low privilege—can directly navigate to the XPath Configuration Viewer page. No additional authentication or special network position is required beyond being able to access the Jenkins web interface [1][2].

By accessing this page, the attacker can view the XPath configuration settings, which may contain sensitive information about the Jenkins environment or job configurations. This information leakage could aid in further attacks or expose internal details [1].

The vulnerability is fixed in XPath Configuration Viewer Plugin version 1.1.2. Users should upgrade to this version or later. There is no known workaround, and the plugin is not listed on CISA's Known Exploited Vulnerabilities catalog as of the advisory date [1].

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.jenkins-ci.plugins:xpath-config-viewerMaven
<= 1.1.1

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.