CVE-2022-20616: Medium severity jenkins credentials binding vulnerability
Jenkins Credentials Binding Plugin 1.27 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read access to validate if a credential ID refers to a secret file credential and whether it's a zip file.
Other sources
Jenkins Credentials Binding Plugin prior to 1.27.1 and 1.24.1 does not perform a permission check in a method implementing form validation.
This allows attackers with Overall/Read access to validate if a credential ID refers to a secret file credential and whether it’s a zip file.
Credentials Binding Plugin 1.27.1 and 1.24.1 performs permission checks when validating secret file credentials IDs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-20616?
CVE-2022-20616 is considered a medium severity vulnerability.
How do I fix CVE-2022-20616?
To fix CVE-2022-20616, update the Jenkins Credentials Binding Plugin to version 1.27.1 or later.
What systems are affected by CVE-2022-20616?
CVE-2022-20616 affects Jenkins Credentials Binding Plugin versions 1.27 and earlier.
What kind of attack does CVE-2022-20616 allow?
CVE-2022-20616 allows attackers with Overall/Read access to validate credential IDs and check if they refer to secret file credentials.
When was CVE-2022-20616 disclosed?
CVE-2022-20616 was disclosed on January 12, 2022.