cbcvebase.
CVE-2022-41252
published 2022-09-21

CVE-2022-41252: Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allows users with Overall/Read permission to enumerate credentials ID of credentials…

PriorityP420medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.54%
41.9th percentile
Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allows users with Overall/Read permission to enumerate credentials ID of credentials stored in Jenkins.

Affected

23 ranges
VendorProductVersion rangeFixed in
jenkinsanchore_container_image_scanner_plugin
jenkinsapprenda_plugin
jenkinsbigpanda_notifier_plugin
jenkinsbmc_ami_common_configuration_plugin
jenkinscons3rt<= 1.0.0
jenkinscons3rt_plugin
jenkinsdotci_plugin
jenkinsjenkins_core
jenkinsjenkins_weekly
jenkinslack_of_authentication_mechanism_in_dotci_plugin
jenkinsns-nd_integration_performance_publisher_plugin
jenkinsrqm_plugin
jenkinsrundeck_plugin
jenkinsscm_httpclient_plugin
jenkinssecurity_inspector_plugin
jenkinssmalltest_plugin
jenkinsthis_could_create_confusion_in_users_of_the_plugin
jenkinsurls_of_jenkins_servers_that_the_plugin
jenkinsview26_test-reporting_plugin
jenkinswalti_plugin
jenkinswildfly_deployer_plugin
jenkinsworksoft_execution_manager_plugin
jenkins_projectjenkins_cons3rt_pluginunspecified – 1.0.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.