CVE-2022-41254
Description
Missing permission checks in Jenkins CONS3RT Plugin allow attackers with Overall/Read permission to connect to attacker-specified servers and capture credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Missing permission checks in Jenkins CONS3RT Plugin allow attackers with Overall/Read permission to connect to attacker-specified servers and capture credentials.
Vulnerability
Description
The Jenkins CONS3RT Plugin, version 1.0.0 and earlier, contains missing permission checks that allow attackers who have the Overall/Read permission to connect to an attacker-specified HTTP server [1][3]. The attacker can specify credentials IDs obtained through another method, effectively capturing those credentials stored in Jenkins during the connection attempt [1][2].
Attack
Surface and Prerequisites
To exploit this vulnerability, an attacker must first have Overall/Read permission in a Jenkins environment — a relatively low-privilege access level. They also need to obtain valid credential IDs from Jenkins through separate means (e.g., by exploiting another vulnerability or through configuration exposure). Once these prerequisites are met, the attacker can craft malicious requests that cause the plugin to connect to their controlled HTTP server using those credentials, leading to their exfiltration [1][2].
Impact
Successful exploitation results in the disclosure of Jenkins credentials, which could be used to gain more privileged access to Jenkins or to other systems that those credentials are intended for. This undermines the security of the Jenkins instance and any external services integrated via credentials [1][3].
Mitigation
At the time of publication (2022-09-21), there was no fixed version available for the CONS3RT Plugin; it remained unresolved [1][2]. Users are advised to restrict the Overall/Read permission to trusted users, monitor for suspicious connections, and consider removing or disabling the plugin if it is not essential. The vulnerability was noted in the Jenkins security advisory but no patch had been released [1][2].
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:cons3rtMaven | <= 1.0.0 | — |
Affected products
2- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/advisories/GHSA-74x9-fhc2-p79fghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-41254ghsaADVISORY
- www.openwall.com/lists/oss-security/2022/09/21/5ghsamailing-listx_refsource_MLISTWEB
- www.jenkins.io/security/advisory/2022-09-21/ghsax_refsource_CONFIRMWEB
News mentions
1- Jenkins Security Advisory 2022-09-21Jenkins Security Advisories · Sep 21, 2022