CVE-2022-25204

MEDIUM

Jenkins Doktor Plugin <0.4.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

Jenkins Doktor Plugin 0.4.1 and earlier implements functionality that allows agent processes to render files on the controller as Markdown or Asciidoc, and error messages allow attackers able to control agent processes to determine whether a file with a given name exists.

References (1)

Core 1
Core References
Issue Tracking, Patch, Vendor Advisory x_refsource_confirm
https://www.jenkins.io/security/advisory/2022-02-15/#SECURITY-2548

Scores

CVSS v3 5.4
EPSS 0.0005
EPSS Percentile 14.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Details

Status published
Products (2)
by.dev.madhead.doktor/doktor 0Maven
jenkins/doktor < 0.4.1
Published Feb 15, 2022
Tracked Since Feb 18, 2026