First published: Tue Feb 15 2022(Updated: )
Jenkins Support Core Plugin 2.79 and earlier does not redact some sensitive information in the support bundle.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.jenkins-ci.plugins:support-core | <2.79.1 | 2.79.1 |
Jenkins Support Core | <=2.79 | |
<=2.79 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25187 is considered a moderate severity vulnerability since it can expose sensitive information in support bundles.
To fix CVE-2022-25187, update the Jenkins Support Core Plugin to version 2.79.1 or later.
CVE-2022-25187 affects sensitive information that may include credentials or configuration details not properly redacted in support bundles.
Versions of Jenkins Support Core Plugin up to and including 2.79 are vulnerable to CVE-2022-25187.
Yes, CVE-2022-25187 specifically affects the Jenkins Support Core Plugin.