CVE-2022-25199

CVSS v3.1 8.8 (High)
88% Progress
CVSS v2.0 6.5 (Medium)
65% Progress
EPSS 0.09 % (37th)
0.09% Progress
Affected Products 1
Advisories 2

A missing permission check in Jenkins SCP publisher Plugin 1.8 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials.

Weaknesses
CWE-862
Missing Authorization
CVE Status
PUBLISHED
CNA
Jenkins Project
Published Date
2022-02-15 17:15:10
(2 years ago)
Updated Date
2023-11-03 16:22:08
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Jenkins Scp Publisher for Jenkins 1.8 and prior versions cpe:2.3:a:jenkins:scp_publisher::*:*:*:*:jenkins <= 1.8
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...