CVE-2022-25211: High severity jenkins swarm vulnerability
Published Feb 15, 2022
·Updated
A missing permission check in Jenkins SWAMP Plugin 1.2.6 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified web server using attacker-specified credentials.
Affected Software
1 affected component
Jenkins Swamp Jenkins<=1.2.6
Event History
Feb 15, 2022
CVE Published
via MITRE·04:11 PM
Data Sourced
via MITRE·04:11 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-25211?
CVE-2022-25211 has been rated as a high severity vulnerability due to the potential for unauthorized access to web servers.
2
How do I fix CVE-2022-25211?
To fix CVE-2022-25211, upgrade the Jenkins SWAMP Plugin to version 1.2.7 or later.
3
What causes CVE-2022-25211?
CVE-2022-25211 is caused by a missing permission check in the Jenkins SWAMP Plugin.
4
Who is affected by CVE-2022-25211?
Users of Jenkins SWAMP Plugin versions 1.2.6 and earlier are affected by CVE-2022-25211.
5
What are the potential impacts of CVE-2022-25211?
The potential impacts of CVE-2022-25211 include unauthorized connections to web servers using attacker-specified credentials.