CVE-2022-41254: Medium severity Jenkins Cons3rt Jenkins vulnerability
Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-41254?
CVE-2022-41254 is rated as a high-severity vulnerability due to its potential for unauthorized credential access.
How do I fix CVE-2022-41254?
To mitigate CVE-2022-41254, upgrade the Jenkins CONS3RT Plugin to version 1.0.1 or later where the permission checks are properly implemented.
Who is affected by CVE-2022-41254?
All Jenkins installations using the CONS3RT Plugin version 1.0.0 and earlier are affected by CVE-2022-41254.
What risks are associated with CVE-2022-41254?
CVE-2022-41254 allows attackers to connect to malicious HTTP servers and potentially capture sensitive Jenkins credentials.
What should I do if I cannot upgrade due to compatibility issues related to CVE-2022-41254?
If an upgrade is not feasible, restrict permissions to Overall/Read for users to mitigate the risk of CVE-2022-41254.