CVE-2022-34811
Description
Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier lacks a permission check, allowing attackers with Overall/Read permission to access the XPath Configuration Viewer page.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier lacks a permission check, allowing attackers with Overall/Read permission to access the XPath Configuration Viewer page.
The Jenkins XPath Configuration Viewer Plugin up to version 1.1.1 fails to perform a proper permission check when rendering the XPath Configuration Viewer page. This missing authorization allows any user with the Overall/Read permission to view the page, which should require a higher privilege level such as Overall/Administer [1].
An attacker who has already obtained Overall/Read access to a Jenkins instance—a relatively low privilege—can directly navigate to the XPath Configuration Viewer page. No additional authentication or special network position is required beyond being able to access the Jenkins web interface [1][2].
By accessing this page, the attacker can view the XPath configuration settings, which may contain sensitive information about the Jenkins environment or job configurations. This information leakage could aid in further attacks or expose internal details [1].
The vulnerability is fixed in XPath Configuration Viewer Plugin version 1.1.2. Users should upgrade to this version or later. There is no known workaround, and the plugin is not listed on CISA's Known Exploited Vulnerabilities catalog as of the advisory date [1].
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:xpath-config-viewerMaven | <= 1.1.1 | — |
Affected products
2- Jenkins project/Jenkins XPath Configuration Viewer Pluginv5Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-qm37-c4w6-h9v9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-34811ghsaADVISORY
- www.jenkins.io/security/advisory/2022-06-30/ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.