CVE-2022-30948: High severity mercurial vulnerability
A flaw was found in the Jenkins plugin. Affected versions of the Jenkins Mercurial Plugin allow attackers who can configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system. This is accomplished by using local paths as SCM URLs, obtaining limited information about other projects' SCM contents.
Other sources
Jenkins Mercurial Plugin 2.16 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM contents.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-30948?
CVE-2022-30948 is considered a medium severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2022-30948?
To mitigate CVE-2022-30948, update the Jenkins Mercurial Plugin to version 2.17 or later.
What does CVE-2022-30948 affect?
CVE-2022-30948 affects Jenkins Mercurial Plugin versions 2.16 and earlier.
What vulnerability does CVE-2022-30948 exploit?
CVE-2022-30948 exploits the ability for attackers to configure pipelines to access restricted SCM repository paths on the Jenkins controller.
Can CVE-2022-30948 lead to unauthorized access?
Yes, CVE-2022-30948 can lead to unauthorized access to limited information about other projects' SCM contents through insecure configuration.