Rewterz
Rewterz Threat Advisory – CVE-2022-45390 – Jenkins loader.io Plugin Vulnerability
November 16, 2022
Rewterz
Rewterz Threat Alert – APT32 Ocean Lotus – Active IOCs
November 16, 2022

Rewterz Threat Advisory – Jenkins NS-ND Integration Performance Publisher Plugin Vulnerabilities

Severity

High

Analysis Summary

CVE-2022-45391 CVSS:7.1
Jenkins NS-ND Integration Performance Publisher Plugin could allow a remote authenticated attacker to obtain sensitive information, caused by the disable of SSL/TLS certificate and hostname validation. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.

CVE-2022-45392 CVSS:4.3
Jenkins NS-ND Integration Performance Publisher Plugin could allow a remote authenticated attacker to obtain sensitive information, caused by the storage of passwords unencrypted in job config.xml files. By gaining access to the job config.xml file, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.

CVE-2022-38666 CVSS:5.9
Jenkins NS-ND Integration Performance Publisher Plugin could allow a remote authenticated attacker to obtain sensitive information, caused by the disable of SSL/TLS certificate and hostname validation. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.

Impact

  • Information Disclosure

Indicators Of Compromise

CVE

  • CVE-2022-45391
  • CVE-2022-45392
  • CVE-2022-38666

Affected Vendors

Jenkins

Affected Products

Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143

Remediation

Refer to Jenkins Security Advisory for patch, upgrade or suggested workaround information. 
Jenkins Security Advisory