CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2022-43410: Jenkins Mercurial Plugin 1251.va_b_121f184902 and earlier provides information about which jobs were triggered or scheduled for polling through its webhook endpoint, including jobs the user has no permission to access.

mediumCVSS 5.3CVE-2022-43410

CSIRTS triage

vendor: Jenkinsproduct: Mercurial PluginInformation disclosureaffected: 1251.va_b_121f184902 and earlier
What
Jenkins Mercurial Plugin webhook endpoint reveals job names and polling information without proper authorization checks.
Who is affected
Jenkins instances with Mercurial Plugin installed, accessible to users without job permissions.
Urgency
Medium priority; information disclosure affecting job confidentiality, not currently exploited.
Action
Upgrade Jenkins Mercurial Plugin to version after 1251.va_b_121f184902.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Mercurial Plugin

Get an email when a new Mercurial Plugin advisory drops — max one per day, one-click unsubscribe.

Details

Source
Microsoft Security Response Center (INTL · vendor-psirt · site)
Severity
medium — CVSS 5.3
Published
2026-08-06
Exploitation
Not in CISA KEV at last sync

Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-43410

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2022-43410coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Microsoft Security Response Center