Vulnerability Description
Jenkins Pipeline: Build Step Plugin 2.15 and earlier reveals password parameter default values when generating a pipeline script using the Pipeline Snippet Generator, allowing attackers with Item/Read permission to retrieve the default password parameter value from jobs.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jenkins | Pipeline\ | <= 2.15, _build_step |
Related Weaknesses (CWE)
References
- https://www.jenkins.io/security/advisory/2022-02-15/#SECURITY-2519PatchVendor Advisory
- https://www.jenkins.io/security/advisory/2022-02-15/#SECURITY-2519PatchVendor Advisory
FAQ
What is CVE-2022-25184?
CVE-2022-25184 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Jenkins Pipeline: Build Step Plugin 2.15 and earlier reveals password parameter default values when generating a pipeline script using the Pipeline Snippet Generator, allowing attackers with Item/Read...
How severe is CVE-2022-25184?
CVE-2022-25184 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-25184?
Check the references section above for vendor advisories and patch information. Affected products include: Jenkins Pipeline\.