Medium severity5.4NVD Advisory· Published Jul 27, 2022· Updated Jun 17, 2026
CVE-2022-36910
CVE-2022-36910
Description
Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to reindex the database and to obtain information about jobs otherwise inaccessible to them.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:lucene-searchMaven | < 387.v938a | 387.v938a |
Affected products
3- Range: unspecified
- cpe:2.3:a:jenkins:lucene-search:*:*:*:*:*:jenkins:*:*Range: <=370.v62a5f618cd3a
Patches
Vulnerability mechanics
References
5- www.openwall.com/lists/oss-security/2022/07/27/1nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-m8w5-vwq3-gp8fghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-36910ghsaADVISORY
- www.jenkins.io/security/advisory/2022-07-27/nvdVendor AdvisoryWEB
- github.com/jenkinsci/lucene-search-plugin/commit/b56e0aba81a355356d20824e81038e9720bc7e2eghsaWEB
News mentions
0No linked articles in our index yet.