CVE-2022-41228 is a missing permission check vulnerability in the Jenkins NS-ND Integration Performance Publisher Plugin versions 4.8.0.129 and earlier. This flaw allows authenticated attackers with Overall/Read permissions to force the plugin to connect to an arbitrary web server using attacker-provided credentials. The vulnerability carries a high CVSS score of 8.8, indicating a critical severity. Its attack vector is network-based with low attack complexity, and successful exploitation can lead to high impacts on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, and no public exploit code or Metasploit modules are available. The vulnerability has received minimal community discussion and media coverage, suggesting it is not widely known or actively targeted.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.8.0.130CPE matchmatch criteria | cpe:2.3:a:jenkins:ns-nd_integration_performance_publisher:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.