CVE-2022-28158: Medium severity jenkins pipeline vulnerability
Published Mar 29, 2022
·Updated
A missing permission check in Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Affected Software
2 affected components
maven/com.surenpi.jenkins:phoenix-autotest<=1.3
Jenkins Pipeline\<=1.3
Event History
Mar 29, 2022
CVE Published
via MITRE·12:31 PM
Data Sourced
via MITRE·12:31 PM
Description
Mar 30, 2022
Advisory Published
12:00 AM
Frequently Asked Questions
1
What is the severity of CVE-2022-28158?
CVE-2022-28158 is classified as a high severity vulnerability due to its potential impact on credential leakage in Jenkins.
2
How do I fix CVE-2022-28158?
To fix CVE-2022-28158, update Jenkins Pipeline: Phoenix AutoTest Plugin to version 1.4 or later.
3
What impact does CVE-2022-28158 have on Jenkins users?
CVE-2022-28158 allows attackers with Overall/Read permission to enumerate stored credential IDs, posing a risk of unauthorized access.
4
Can CVE-2022-28158 be exploited remotely?
Yes, CVE-2022-28158 can be exploited remotely by authenticated users with minimal permissions.
5
What versions of the Phoenix AutoTest Plugin are affected by CVE-2022-28158?
Versions 1.3 and earlier of the Jenkins Pipeline: Phoenix AutoTest Plugin are affected by CVE-2022-28158.