Information Disclosure Vulnerability in Jenkins Mercurial Plugin
CVE-2022-43410
5.3MEDIUM
What is CVE-2022-43410?
The Jenkins Mercurial Plugin, specifically versions 1251.va_b_121f184902 and earlier, contains a vulnerability that allows unauthorized access to information about triggered or scheduled jobs via its webhook endpoint. This flaw exposes job details to users who typically do not have permission to view that information, potentially leading to unauthorized insights into project activities and workflows.
Affected Version(s)
Jenkins Mercurial Plugin <= 1251.va_b_121f184902