VYPR
High severityNVD Advisory· Published May 17, 2022· Updated Aug 3, 2024

CVE-2022-30958

CVE-2022-30958

Description

CSRF in Jenkins SSH Plugin 2.6.1 and earlier allows attackers to connect to an attacker-specified SSH server using stolen credentials, capturing Jenkins credentials.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CSRF in Jenkins SSH Plugin 2.6.1 and earlier allows attackers to connect to an attacker-specified SSH server using stolen credentials, capturing Jenkins credentials.

Vulnerability

A cross-site request forgery (CSRF) vulnerability exists in Jenkins SSH Plugin version 2.6.1 and earlier [1][2]. The plugin does not require a CSRF token or other validation for requests that initiate SSH connections. This allows an attacker to trick a Jenkins administrator or user with appropriate permissions into making an unintended request.

Exploitation

An attacker must first obtain valid credential IDs from Jenkins (e.g., through another vulnerability or information disclosure) [1]. Then, by crafting a malicious web page or link, the attacker can trigger a CSRF request from an authenticated Jenkins user. The request causes Jenkins to connect to an attacker-specified SSH server using the stolen credential IDs, effectively capturing those credentials.

Impact

Successful exploitation allows the attacker to capture Jenkins-stored SSH credentials by having Jenkins connect to a server under the attacker's control [1][2]. The attacker gains the ability to use those credentials for further unauthorized access. The impact is limited to credential disclosure; no remote code execution is directly achieved.

Mitigation

Jenkins SSH Plugin version 2.6.2 and later includes a CSRF protection mechanism [1]. Users should upgrade to version 2.6.2 or newer. No workaround is provided for earlier versions. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog as of the advisory date.

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.jenkins-ci.plugins:sshMaven
<= 2.6.1

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

1