CVE-2022-28141 describes a vulnerability in Jenkins Proxmox Plugin versions 0.5.0 and earlier, where the Proxmox Datacenter password is stored unencrypted in the global config.xml file on the Jenkins controller. This allows users with file system access to the controller to view the sensitive password. The vulnerability has a CVSS score of 6.5 (Medium), indicating a low attack complexity and requiring low privileges, but leading to high confidentiality impact as an attacker could gain unauthorized access to Proxmox. There is no impact on integrity or availability. Currently, there is no evidence of active exploitation, nor is there any publicly available exploit code in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting it has not garnered significant attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.5.0CPE matchmatch criteria | cpe:2.3:a:jenkins:proxmox:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.