Jenkins Convertigo Mobile Platform Plugin Vulnerability Exposes Job Configurations
CVE-2022-25210
6.5MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 15 February 2022
What is CVE-2022-25210?
The Jenkins Convertigo Mobile Platform Plugin, version 1.1 and earlier, is vulnerable to an insecure direct object reference. This vulnerability occurs when static fields are utilized to store job configuration details, which leads to a situation where users with Item/Configure permissions can potentially access and capture the passwords associated with the job configurations. This poses a significant security risk, allowing unauthorized parties to exploit sensitive information.
Affected Version(s)
Jenkins Convertigo Mobile Platform Plugin <= 1.1