PT-2022-25758 · Jenkins · Jenkins Smalltest Plugin+1

Long Nguyen

·

Published

2022-09-21

·

Updated

2025-05-28

·

CVE-2022-41243

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins SmallTest Plugin versions 1.0.4 and earlier
Description The issue is related to the lack of hostname validation when connecting to the configured View26 server. This could be exploited using a man-in-the-middle attack to intercept these connections. There is no information provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For Jenkins SmallTest Plugin versions 1.0.4 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2022-41243
GHSA-7JWG-HQ85-C6M6

Affected Products

Jenkins
Jenkins Smalltest Plugin