CVE-2022-27195

MEDIUM

Jenkins Parameterized Trigger Plugin <2.43 - Info Disclosure

Title source: llm
STIX 2.1

Description

Jenkins Parameterized Trigger Plugin 2.43 and earlier captures environment variables passed to builds triggered using Jenkins Parameterized Trigger Plugin, including password parameter values, in their `build.xml` files. These values are stored unencrypted and can be viewed by users with access to the Jenkins controller file system.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2022/03/15/2

Scores

CVSS v3 5.5
EPSS 0.0041
EPSS Percentile 61.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

Status published
Products (2)
jenkins/parameterized_trigger < 2.43.1
org.jenkins-ci.plugins/parameterized-trigger 0 - 2.43.1Maven
Published Mar 15, 2022
Tracked Since Feb 18, 2026