Rewterz Threat Advisory – CVE-2022-45390 – Jenkins loader.io Plugin Vulnerability
November 16, 2022Rewterz Threat Alert – APT32 Ocean Lotus – Active IOCs
November 16, 2022Rewterz Threat Advisory – CVE-2022-45390 – Jenkins loader.io Plugin Vulnerability
November 16, 2022Rewterz Threat Alert – APT32 Ocean Lotus – Active IOCs
November 16, 2022Severity
High
Analysis Summary
CVE-2022-45391 CVSS:7.1
Jenkins NS-ND Integration Performance Publisher Plugin could allow a remote authenticated attacker to obtain sensitive information, caused by the disable of SSL/TLS certificate and hostname validation. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.
CVE-2022-45392 CVSS:4.3
Jenkins NS-ND Integration Performance Publisher Plugin could allow a remote authenticated attacker to obtain sensitive information, caused by the storage of passwords unencrypted in job config.xml files. By gaining access to the job config.xml file, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.
CVE-2022-38666 CVSS:5.9
Jenkins NS-ND Integration Performance Publisher Plugin could allow a remote authenticated attacker to obtain sensitive information, caused by the disable of SSL/TLS certificate and hostname validation. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.
Impact
- Information Disclosure
Indicators Of Compromise
CVE
- CVE-2022-45391
- CVE-2022-45392
- CVE-2022-38666
Affected Vendors
Jenkins
Affected Products
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143
Remediation
Refer to Jenkins Security Advisory for patch, upgrade or suggested workaround information.
Jenkins Security Advisory