CVE-2022-41230

MEDIUM

Jenkins Build-Publisher Plugin <1.22 - Info Disclosure

Title source: llm
STIX 2.1

Description

Jenkins Build-Publisher Plugin 1.22 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to obtain names and URLs of Jenkins servers that the plugin is configured to publish builds to, as well as builds pending for publication to those Jenkins servers.

References (1)

Core 1
Core References

Scores

CVSS v3 4.3
EPSS 0.0025
EPSS Percentile 48.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (2)
jenkins/build-publisher < 1.22
org.jenkins-ci.plugins/build-publisher 0Maven
Published Sep 21, 2022
Tracked Since Feb 18, 2026