Lucene search

K
cveJenkinsCVE-2022-36901
HistoryJul 27, 2022 - 3:15 p.m.

CVE-2022-36901

2022-07-2715:15:09
CWE-522
jenkins
web.nvd.nist.gov
55
3
jenkins
http request
plugin
passwords
unencrypted
security vulnerability
cve-2022-36901

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

28.4%

Jenkins HTTP Request Plugin 1.15 and earlier stores HTTP Request passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

Affected configurations

Nvd
Node
jenkinshttp_requestRange1.15jenkins
VendorProductVersionCPE
jenkinshttp_request*cpe:2.3:a:jenkins:http_request:*:*:*:*:*:jenkins:*:*

CNA Affected

[
  {
    "product": "Jenkins HTTP Request Plugin",
    "vendor": "Jenkins project",
    "versions": [
      {
        "lessThanOrEqual": "1.15",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThan": "unspecified",
        "status": "unknown",
        "version": "next of 1.15",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

28.4%

Related for CVE-2022-36901