CVE-2022-28146

CWE-22Path Traversal5 documents5 sources
Severity
6.5MEDIUM
EPSS
0.8%
top 25.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 29
Latest updateMar 30

Description

Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier allows attackers with Item/Configure permission to read arbitrary files on the Jenkins controller by specifying an input folder on the Jenkins controller as a parameter to its build steps.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

🔴Vulnerability Details

3
OSV
Arbitrary file read vulnerability in Jenkins Continuous Integration with Toad Edge Plugin2022-03-30
GHSA
Arbitrary file read vulnerability in Jenkins Continuous Integration with Toad Edge Plugin2022-03-30
CVEList
CVE-2022-28146: Jenkins Continuous Integration with Toad Edge Plugin 22022-03-29

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2022-03-292022-03-29
CVE-2022-28146 (MEDIUM CVSS 6.5) | Jenkins Continuous Integration with | cvebase.io