Moderate severityNVD Advisory· Published May 17, 2022· Updated Aug 3, 2024
CVE-2022-30952
CVE-2022-30952
Description
Jenkins Pipeline SCM API for Blue Ocean Plugin 1.25.3 and earlier allows attackers with Job/Configure permission to access credentials with attacker-specified IDs stored in the private per-user credentials stores of any attacker-specified user in Jenkins.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
io.jenkins.blueocean:blueocean-pipeline-scm-apiMaven | < 1.25.4 | 1.25.4 |
Affected products
2- Jenkins project/Jenkins Pipeline SCM API for Blue Ocean Pluginv5Range: unspecified
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-g74w-93cp-5p3pghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-30952ghsaADVISORY
- www.openwall.com/lists/oss-security/2022/05/17/8ghsamailing-listWEB
- github.com/jenkinsci/blueocean-plugin/commit/c4beeda0b574c297ac664511029feed0a15abaf1ghsaWEB
- github.com/jenkinsci/blueocean-plugin/tree/master/blueocean-pipeline-scm-apighsaPACKAGE
- www.jenkins.io/security/advisory/2022-05-17/ghsaWEB
News mentions
1- Jenkins Security Advisory 2022-05-17Jenkins Security Advisories · May 17, 2022