Medium severity5.3NVD Advisory· Published May 17, 2022· Updated Jun 17, 2026
CVE-2022-30949
CVE-2022-30949
Description
Jenkins REPO Plugin 1.14.0 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM contents.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:repoMaven | < 1.14.1 | 1.14.1 |
org.jenkins-ci.plugins:mercurialMaven | < 2.16.1 | 2.16.1 |
org.jenkins-ci.plugins:gitMaven | < 4.11.2 | 4.11.2 |
Affected products
5- ghsa-coords3 versionspkg:maven/org.jenkins-ci.plugins/gitpkg:maven/org.jenkins-ci.plugins/mercurialpkg:maven/org.jenkins-ci.plugins/repo
< 4.11.2+ 2 more
- (no CPE)range: < 4.11.2
- (no CPE)range: < 2.16.1
- (no CPE)range: < 1.14.1
- Range: unspecified
Patches
Vulnerability mechanics
References
7- www.openwall.com/lists/oss-security/2022/05/17/8nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-8vfc-fcr2-47pjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-30949ghsaADVISORY
- www.jenkins.io/security/advisory/2022-05-17/nvdVendor AdvisoryWEB
- github.com/jenkinsci/git-plugin/commit/b295606e0b865c298fde27bea14f9b7535a976e6ghsaWEB
- github.com/jenkinsci/mercurial-plugin/commit/55904fbb8c9d3e0b36fc26330374904cb68e8758ghsaWEB
- github.com/jenkinsci/repo-plugin/commit/8c9cbb88baffc64d1b63183235eb86c773108235ghsaWEB
News mentions
1- Jenkins Security Advisory 2022-05-17Jenkins Security Advisories · May 17, 2022