PT-2022-17150 · Jenkins · Jenkins Swamp Plugin+1

Wadeck Follonier

·

Published

2022-02-15

·

Updated

2023-11-22

·

CVE-2022-25211

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins SWAMP Plugin versions 1.2.6 and earlier
Description A missing permission check in the Jenkins SWAMP Plugin allows attackers with Overall/Read permission to connect to an attacker-specified web server using attacker-specified credentials. This issue enables attackers to capture credentials stored in Jenkins by connecting to an attacker-specified URL using attacker-specified credentials IDs obtained through another method.
Recommendations For Jenkins SWAMP Plugin versions 1.2.6 and earlier, consider disabling the plugin until a patch is available to prevent attackers from exploiting the missing permission check. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-25211
GHSA-8P8Q-WVXX-JQ94

Affected Products

Jenkins
Jenkins Swamp Plugin