CVE Vulnerabilities

CVE-2022-30948

Published: May 17, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Ubuntu

Jenkins Mercurial Plugin 2.16 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controllers file system using local paths as SCM URLs, obtaining limited information about other projects SCM contents.

Affected Software

Name Vendor Start Version End Version
Mercurial Jenkins * 2.16.1 (excluding)
Red Hat OpenShift Container Platform 4.8 RedHat jenkins-2-plugins-0:4.8.1672842762-1.el8 *

References