CVE-2022-45399
Description
A missing permission check in Jenkins Cluster Statistics Plugin 0.4.6 and earlier allows attackers to delete recorded cluster statistics, leading to data loss.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A missing permission check in Jenkins Cluster Statistics Plugin 0.4.6 and earlier allows attackers to delete recorded cluster statistics, leading to data loss.
Vulnerability
Description
The Jenkins Cluster Statistics Plugin versions 0.4.6 and earlier contains a missing permission check [1]. This flaw allows an attacker to delete recorded Jenkins Cluster Statistics without proper authorization [2]. The root cause is the absence of an access control mechanism on the functionality responsible for deleting statistics data.
Attack
Vector and Prerequisites
An attacker can exploit this vulnerability by sending a crafted HTTP request to a Jenkins instance running an affected version of the plugin [3]. No authentication is required if the Jenkins instance is configured to allow unauthenticated access, but in typical setups, the attacker would need at least Overall/Read permission to reach the plugin's endpoints [2]. The attack is network-based, meaning remote exploitation is possible.
Impact
Successful exploitation allows an attacker to delete recorded cluster statistics [1]. This can lead to loss of historical data used for monitoring, capacity planning, and troubleshooting. While it does not directly compromise the Jenkins system or its jobs, it disrupts visibility into cluster performance and resource utilization.
Mitigation
As of the Jenkins Security Advisory 2022-11-15, no fix is available for this plugin [2]. The plugin is likely deprecated or unmaintained. Administrators are advised to remove or disable the Cluster Statistics Plugin if it is not needed [1]. There are no known workarounds.
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.zeroturnaround:cluster-statsMaven | <= 0.4.6 | — |
Affected products
2- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/advisories/GHSA-w8wg-62wf-62gmghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-45399ghsaADVISORY
- www.openwall.com/lists/oss-security/2022/11/15/4ghsamailing-listWEB
- www.jenkins.io/security/advisory/2022-11-15/ghsaWEB
News mentions
1- Jenkins Security Advisory 2022-11-15Jenkins Security Advisories · Nov 15, 2022