CVE-2022-41228: High severity Jenkins Ns-nd Integration Performance Publisher Jenkins vulnerability
A missing permission check in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers with Overall/Read permissions to connect to an attacker-specified webserver using attacker-specified credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-41228?
CVE-2022-41228 has a medium severity rating due to unauthorized access that could lead to information disclosure.
How do I fix CVE-2022-41228?
To fix CVE-2022-41228, upgrade to Jenkins NS-ND Integration Performance Publisher Plugin version 4.8.0.130 or later.
Who is affected by CVE-2022-41228?
Users of Jenkins NS-ND Integration Performance Publisher Plugin version 4.8.0.129 and earlier are affected by CVE-2022-41228.
What type of attack does CVE-2022-41228 allow?
CVE-2022-41228 allows attackers to connect to a specified webserver using credentials provided by the attacker.
What permissions are required to exploit CVE-2022-41228?
Attackers need Overall/Read permissions to exploit CVE-2022-41228.