CVE-2022-30948

HIGH

Jenkins Mercurial Plugin <2.16 - Info Disclosure

Title source: llm
STIX 2.1

Description

Jenkins Mercurial Plugin 2.16 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM contents.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2022/05/17/8

Scores

CVSS v3 7.5
EPSS 0.0074
EPSS Percentile 73.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

Status published
Products (2)
jenkins/mercurial < 2.16.1
org.jenkins-ci.plugins/mercurial 0 - 2.16.1Maven
Published May 17, 2022
Tracked Since Feb 18, 2026