CVE-2022-43417: Medium severity Jenkins Katalon Jenkins vulnerability
Jenkins Katalon Plugin 1.0.32 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Jenkins Katalon Plugin vulnerability?
The vulnerability ID for this Jenkins Katalon Plugin vulnerability is CVE-2022-43417.
What is the severity of CVE-2022-43417?
The severity of CVE-2022-43417 is medium.
What software versions are affected by CVE-2022-43417?
Jenkins Katalon Plugin versions up to and excluding 1.0.33 are affected by CVE-2022-43417.
Are permission checks performed in all HTTP endpoints of Jenkins Katalon Plugin?
No, Jenkins Katalon Plugin 1.0.32 and earlier do not perform permission checks in several HTTP endpoints.
How can an attacker exploit CVE-2022-43417?
An attacker with Overall/Read permission can connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins Katalon Plugin 1.0.32 and earlier.