Missing Permission Check in Jenkins Publish Over SSH Plugin
CVE-2022-23112
6.5MEDIUM
Key Information:
- Vendor
- Jenkins
- Vendor
- CVE Published:
- 12 January 2022
Summary
A security vulnerability in the Jenkins Publish Over SSH Plugin allows attackers with Overall/Read access to connect to arbitrary SSH servers using attacker-specified credentials. This oversight could potentially expose sensitive information and allow unauthorized actions on remote servers, emphasizing the importance of securing such plugins to prevent misuse.
Affected Version(s)
Jenkins Publish Over SSH Plugin <= 1.22
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved