Jenkins Security Advisory 2022-05-17
Affects plugin: Application Detector Affects plugin: Autocomplete Parameter Affects plugin: Blue Ocean Affects plugin: Git Affects plugin: GitLab Affects plugin: Global Variable String Parameter Affects plugin: JDK Parameter Affects plugin: Mercurial Affects plugin: Multiselect parameter Affects plugin: Pipeline SCM API for Blue Ocean Affects plugin: Pipeline: Groovy Affects plugin: Promoted Builds (Simple) Affects plugin: Random String Parameter Affects plugin: REPO Affects plugin: Rundeck Affects plugin: Script Security Affects plugin: Selection tasks Affects plugin: SSH Affects plugin: Storable Configs Affects plugin: vboxwrapper Affects plugin: windows-slaves
CSIRTS triage
- What
- Multiple plugins in Jenkins are affected by various vulnerabilities.
- Who is affected
- Deployments of Jenkins with the affected plugins.
- Urgency
- Remediation is urgent due to the potential for exploitation, although the severity is unknown.
- Action
- Update the affected plugins to their latest versions.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Jenkins
Get an email when a new Jenkins advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.jenkins.io/security/advisory/2022-05-17/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2022-309451.4% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 69% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2022-309460.63% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 47% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2022-309471.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 67% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2022-309481.5% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 71% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2022-309491.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 60% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2022-309501.8% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 77% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2022-309510.87% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 56% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2022-309520.98% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 59% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2022-309530.70% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 50% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2022-309540.88% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 56% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownJenkins Security Advisory 2022-10-19jenkins
- unknownJenkins Security Advisory 2022-06-30jenkins
- unknownJenkins Security Advisory 2022-06-22jenkins
- unknownJenkins Security Advisory 2022-04-12jenkins
More from Jenkins Security Advisories
- unknownJenkins Security Advisory 2026-08-052026-08-05
- unknownJenkins Security Advisory 2026-06-242026-06-24
- unknownJenkins Security Advisory 2026-06-102026-06-10
- unknownJenkins Security Advisory 2026-05-272026-05-27
- unknownJenkins Security Advisory 2026-04-292026-04-29