CVE-2022-25208 is a missing permission check vulnerability in Jenkins Chef Sinatra Plugin versions 1.20 and earlier. This allows authenticated attackers with Overall/Read permission to force Jenkins to send HTTP requests to arbitrary URLs and parse XML responses. Rated with a CVSS score of 8.8 (HIGH), this vulnerability has a low attack complexity and can lead to high impact on confidentiality, integrity, and availability. There is currently no public exploit code available, no evidence of active exploitation, and minimal community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.20CPE matchmatch criteria | cpe:2.3:a:jenkins:chef_sinatra:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.