CVE-2022-25210: Medium severity jenkins convertigo mobile platform vulnerability
Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier uses static fields to store job configuration information, allowing attackers with Item/Configure permission to capture passwords of the jobs that will be configured.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-25210?
CVE-2022-25210 has a medium severity rating due to the potential exposure of sensitive job configuration data.
How do I fix CVE-2022-25210?
To remediate CVE-2022-25210, update the Jenkins Convertigo Mobile Platform Plugin to version 1.2 or later.
Who is affected by CVE-2022-25210?
Any Jenkins instance running Convertigo Mobile Platform Plugin version 1.1 or earlier is vulnerable to CVE-2022-25210.
What type of permissions are required to exploit CVE-2022-25210?
An attacker would need Item/Configure permission in Jenkins to exploit CVE-2022-25210 and capture sensitive passwords.
What kind of information can attackers capture due to CVE-2022-25210?
Attackers can capture passwords associated with job configurations due to the vulnerabilities in how job information is stored.