cbcvebase.
CVE-2022-41255
published 2022-09-21

CVE-2022-41255: Jenkins CONS3RT Plugin 1.0.0 and earlier stores Cons3rt API token unencrypted in job config.xml files on the Jenkins controller where it can be viewed by users…

PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.68%
48.1th percentile
Jenkins CONS3RT Plugin 1.0.0 and earlier stores Cons3rt API token unencrypted in job config.xml files on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

Affected

23 ranges
VendorProductVersion rangeFixed in
jenkinsanchore_container_image_scanner_plugin
jenkinsapprenda_plugin
jenkinsbigpanda_notifier_plugin
jenkinsbmc_ami_common_configuration_plugin
jenkinscons3rt<= 1.0.0
jenkinscons3rt_plugin
jenkinsdotci_plugin
jenkinsjenkins_core
jenkinsjenkins_weekly
jenkinslack_of_authentication_mechanism_in_dotci_plugin
jenkinsns-nd_integration_performance_publisher_plugin
jenkinsrqm_plugin
jenkinsrundeck_plugin
jenkinsscm_httpclient_plugin
jenkinssecurity_inspector_plugin
jenkinssmalltest_plugin
jenkinsthis_could_create_confusion_in_users_of_the_plugin
jenkinsurls_of_jenkins_servers_that_the_plugin
jenkinsview26_test-reporting_plugin
jenkinswalti_plugin
jenkinswildfly_deployer_plugin
jenkinsworksoft_execution_manager_plugin
jenkins_projectjenkins_cons3rt_pluginunspecified – 1.0.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.