CVE-2022-41255
Published on: Not Yet Published
Last Modified on: 09/22/2022 06:47:00 PM UTC
Certain versions of Cons3rt from Jenkins contain the following vulnerability:
Jenkins CONS3RT Plugin 1.0.0 and earlier stores Cons3rt API token unencrypted in job config.xml files on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
- CVE-2022-41255 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
Jenkins project - Jenkins CONS3RT Plugin version <= 1.0.0
- Affected Vendor/Software:
Jenkins project - Jenkins CONS3RT Plugin version ?> 1.0.0
CVSS3 Score: 6.5 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Jenkins Security Advisory 2022-09-21 | www.jenkins.io text/html |
![]() |
oss-security - Multiple vulnerabilities in Jenkins and Jenkins plugins | www.openwall.com text/html |
![]() |
Related QID Numbers
- 730618 Jenkins Cross-Site Scripting (XSS) Vulnerability (Jenkins Security Advisory 2022-09-21)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Jenkins | Cons3rt | All | All | All | All |
- cpe:2.3:a:jenkins:cons3rt:*:*:*:*:*:jenkins:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-41255 : Jenkins CONS3RT Plugin 1.0.0 and earlier stores Cons3rt API token unencrypted in job config.xml fi… twitter.com/i/web/status/1… | 2022-09-21 16:04:39 |
![]() |
New Vulnerability: CVE-2022-41255 #InceptusSecure #UnderOurProtection | 2022-09-21 18:11:21 |
![]() |
Jenkins - CVE-2022-41255: jenkins.io/security/advis… | 2022-09-21 19:00:37 |
![]() |
CVE-2022-41255 | 2022-09-21 16:39:12 |