CVE-2022-25184

MEDIUM

Jenkins Pipeline < 2.15 - Insufficiently Protected Credentials

Title source: rule

Description

Jenkins Pipeline: Build Step Plugin 2.15 and earlier reveals password parameter default values when generating a pipeline script using the Pipeline Snippet Generator, allowing attackers with Item/Read permission to retrieve the default password parameter value from jobs.

Scores

CVSS v3 6.5
EPSS 0.0009
EPSS Percentile 25.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-522
Status published

Affected Products (2)

jenkins/pipeline\ < 2.15
org.jenkins-ci.plugins/pipeline-build-step < 2.15.1Maven

Timeline

Published Feb 15, 2022
Tracked Since Feb 18, 2026