Jenkins Security Advisory 2022-01-12
Affects Jenkins Core Affects plugin: Active Directory Affects plugin: Badge Affects plugin: batch task Affects plugin: Bitbucket Branch Source Affects plugin: Configuration as Code Affects plugin: Conjur Secrets Affects plugin: Credentials Binding Affects plugin: Debian Package Builder Affects plugin: Docker Commons Affects plugin: HashiCorp Vault Affects plugin: Mailer Affects plugin: Matrix Project Affects plugin: Metrics Affects plugin: Publish Over SSH Affects plugin: SSH Agent Affects plugin: Warnings
CSIRTS triage
- What
- Multiple plugins in Jenkins have vulnerabilities that could potentially be exploited.
- Who is affected
- Deployments of Jenkins Core and the listed plugins are affected.
- Urgency
- Remediation is necessary as vulnerabilities exist, although exploitation status is currently unknown.
- Action
- Update to the latest versions of Jenkins Core and the affected plugins.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Jenkins Core
Get an email when a new Jenkins Core advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.jenkins.io/security/advisory/2022-01-12/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2022-206121.8% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 76% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2022-206130.96% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 58% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2022-206141.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 63% of all EPSS-scored CVEs.
- Exploitation likely imminentCVE-2022-20615EPSS puts this in the most-targeted tier (81.8% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 99.6% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2022-206160.85% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 55% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2022-206172.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 82% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2022-206180.85% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 55% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2022-206190.66% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 48% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2022-206200.75% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 52% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2022-206210.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
Referenced CVEs
More from Jenkins Security Advisories
- unknownJenkins Security Advisory 2026-08-052026-08-05
- unknownJenkins Security Advisory 2026-06-242026-06-24
- unknownJenkins Security Advisory 2026-06-102026-06-10
- unknownJenkins Security Advisory 2026-05-272026-05-27
- unknownJenkins Security Advisory 2026-04-292026-04-29