Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-41254
HistorySep 21, 2022 - 4:15 p.m.

Design/Logic Flaw

2022-09-2116:15:00
PRIOn knowledge base
www.prio-n.com
7
jenkins
cons3rt plugin
permission checks
http server
credentials
security flaw

0.001 Low

EPSS

Percentile

28.4%

Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

CPENameOperatorVersion
cons3rtle1.0.0

0.001 Low

EPSS

Percentile

28.4%

Related for PRION:CVE-2022-41254