VYPR
Moderate severityNVD Advisory· Published Sep 21, 2022· Updated May 27, 2025

CVE-2022-41250

CVE-2022-41250

Description

Missing permission check in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers with Overall/Read to capture stored credentials by connecting to attacker-controlled server.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing permission check in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers with Overall/Read to capture stored credentials by connecting to attacker-controlled server.

Vulnerability

Overview

CVE-2022-41250 is a missing permission check in the Jenkins SCM HttpClient Plugin versions 1.5 and earlier. The plugin fails to verify that a user has the necessary permissions to use specified credentials IDs when connecting to an HTTP server. This allows an attacker who already possesses Overall/Read permission (a low-privilege role) to trigger a connection to an attacker-controlled server using credentials IDs obtained through other means [1][2].

Exploitation

Prerequisites

To exploit this vulnerability, an attacker must have Overall/Read permission on the Jenkins instance and must have obtained valid credentials IDs through another method, such as exploiting other vulnerabilities or reading configuration files. The attacker then configures the SCM HttpClient post-build action to connect to their own server, supplying the stolen credentials IDs. The plugin will then send the corresponding credentials to the attacker's server, effectively capturing them [1][2].

Impact

Successful exploitation allows the attacker to capture credentials stored in Jenkins, which may include passwords, API tokens, or SSH keys. These credentials can then be used to further compromise the Jenkins environment or other systems accessible with those credentials [1][2].

Mitigation

Status

As of the Jenkins Security Advisory 2022-09-21, the SCM HttpClient Plugin is listed among plugins with unresolved security issues, meaning no official patch has been released. Users are advised to remove the plugin if not needed, or restrict access to Jenkins to trusted users only [1][2].

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
com.meowlomo.jenkins:scm-httpclientMaven
<= 1.5

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

1