Vulnerability Details CVE-2022-25210
Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier uses static fields to store job configuration information, allowing attackers with Item/Configure permission to capture passwords of the jobs that will be configured.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 69.1%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2022-25210
-
cpe:2.3:a:jenkins:convertigo_mobile_platform:1.0
-
cpe:2.3:a:jenkins:convertigo_mobile_platform:1.1