First published: Tue Feb 15 2022(Updated: )
Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier uses static fields to store job configuration information, allowing attackers with Item/Configure permission to capture passwords of the jobs that will be configured.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Convertigo Mobile Platform | <=1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25210 has a medium severity rating due to the potential exposure of sensitive job configuration data.
To remediate CVE-2022-25210, update the Jenkins Convertigo Mobile Platform Plugin to version 1.2 or later.
Any Jenkins instance running Convertigo Mobile Platform Plugin version 1.1 or earlier is vulnerable to CVE-2022-25210.
An attacker would need Item/Configure permission in Jenkins to exploit CVE-2022-25210 and capture sensitive passwords.
Attackers can capture passwords associated with job configurations due to the vulnerabilities in how job information is stored.