CVE-2022-45392: Medium severity Jenkins Ns-nd Integration Performance Publisher Jenkins vulnerability
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by attackers with Extended Read permission, or access to the Jenkins controller file system.
Other sources
NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller as part of its configuration.
These passwords can be viewed by attackers with Item/Extended Read permission or access to the Jenkins controller file system.
NS-ND Integration Performance Publisher Plugin 4.8.0.146 stores passwords encrypted once job configurations are saved again.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/io.jenkins.plugins:cavisson-ns-nd-integrationto a version that resolves this vulnerability.Fixed in 4.8.0.146 - Upgrade
Upgrade
Jenkins NS-ND Integration Performance Publisher Pluginto a version that resolves this vulnerability.Fixed in 4.8.0.146 - Operational
After upgrading to Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.146, re-save affected job configurations so passwords are stored encrypted (as encryption occurs once job configurations are saved again in 4.8.0.146).
Event History
Frequently Asked Questions
What is the severity of CVE-2022-45392?
CVE-2022-45392 has a moderate severity level due to the risk of sensitive information exposure.
How do I fix CVE-2022-45392?
To mitigate CVE-2022-45392, upgrade to version 4.8.0.146 or later of the Jenkins NS-ND Integration Performance Publisher Plugin.
What types of information are affected by CVE-2022-45392?
CVE-2022-45392 affects passwords stored unencrypted in the job config.xml files on Jenkins controllers.
Who can exploit CVE-2022-45392?
CVE-2022-45392 can be exploited by users with Extended Read permission or access to the Jenkins controller file system.
What plugins are impacted by CVE-2022-45392?
CVE-2022-45392 specifically impacts Jenkins NS-ND Integration Performance Publisher Plugin versions 4.8.0.143 and earlier.