CVE-2022-25180: Medium severity jenkins pipeline vulnerability
A flaw was found in Jenkins. The Pipeline: Groovy Plugin includes password parameters from the original build in replayed builds. This flaw allows attackers with run/replay permission to obtain the values of password parameters passed to previous builds of a Pipeline.
Other sources
Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier includes password parameters from the original build in replayed builds, allowing attackers with Run/Replay permission to obtain the values of password parameters passed to previous builds of a Pipeline.
Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier includes password parameters from the original build in replayed builds.
This allows attackers with Run/Replay permission to obtain the values of password parameters passed to previous builds of a Pipeline.
Pipeline: Groovy Plugin 2656.vf7ae7b75a457 does not allow builds containing password parameters to be replayed.
Pipeline: Groovy Plugin 2648.va9433432b33c and earlier includes password parameters from the original build in replayed builds. This allows attackers with Run/Replay permission to obtain the values of password parameters passed to previous builds of a Pipeline.
References:
https://www.jenkins.io/security/advisory/2022-02-15/
— Red Hat
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2022-25180?
CVE-2022-25180 has a medium severity level as it allows unauthorized access to sensitive password parameters.
How does CVE-2022-25180 affect Jenkins users?
CVE-2022-25180 affects Jenkins users by risking exposure of password parameters from previous builds during build replays.
How do I fix CVE-2022-25180?
To fix CVE-2022-25180, update your Jenkins Pipeline: Groovy Plugin to the latest version available after the remedial version mentioned.
Who is affected by CVE-2022-25180?
Any Jenkins user with run/replay permission on builds using the vulnerable version of the Pipeline: Groovy Plugin is affected by CVE-2022-25180.
What versions of Jenkins are vulnerable to CVE-2022-25180?
Jenkins versions up to 2648.va9433432b33c are vulnerable to CVE-2022-25180.