Jenkins Security Advisory 2022-06-22
Affects Jenkins Core Affects plugin: Agent Server Parameter Affects plugin: Beaker builder Affects plugin: Convertigo Mobile Platform Affects plugin: CRX Content Package Deployer Affects plugin: Date Parameter Affects plugin: Dynamic Extended Choice Parameter Affects plugin: EasyQA Affects plugin: Embeddable Build Status Affects plugin: Filesystem List Parameter Affects plugin: Hidden Parameter Affects plugin: Image Tag Parameter Affects plugin: Jianliao Notification Affects plugin: JUnit Affects plugin: Maven Metadata Plugin for Jenkins CI server Affects plugin: Nested View Affects plugin: NS-ND Integration Performance Publisher Affects plugin: ontrack Jenkins Affects plugin: Package Version Affects plugin: Pipeline: Input Step Affects plugin: Readonly Parameter Affects plugin: Repository Connector Affects plugin: REST List Parameter Affects plugin: Sauce OnDemand Affects plugin: Squash TM Publisher (Squash4Jenkins) Affects plugin: Stash Branch Parameter Affects plugin: ThreadFix Affects plugin: vRealize Orchestrator Affects plugin: xUnit
CSIRTS triage
- What
- Multiple plugins and Jenkins Core are affected by various vulnerabilities.
- Who is affected
- Deployments of Jenkins with the affected plugins and core.
- Urgency
- Remediation is urgent due to the potential for exploitation, although the severity is unknown.
- Action
- Update Jenkins Core and the affected plugins to their latest versions.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Jenkins
Get an email when a new Jenkins advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.jenkins.io/security/advisory/2022-06-22/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2022-341701.4% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 70% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2022-341711.4% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 70% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2022-341721.4% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 70% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2022-341731.4% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 70% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2022-341741.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 68% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2022-341751.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 68% of all EPSS-scored CVEs.
- Exploitation likely imminentCVE-2022-34176EPSS puts this in the most-targeted tier (77.5% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 99.5% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2022-341771.6% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 73% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2022-341780.93% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 57% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2022-341791.6% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 74% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownJenkins Security Advisory 2022-10-19jenkins
- unknownJenkins Security Advisory 2022-06-30jenkins
- unknownJenkins Security Advisory 2022-05-17jenkins
- unknownJenkins Security Advisory 2022-04-12jenkins
More from Jenkins Security Advisories
- unknownJenkins Security Advisory 2026-08-052026-08-05
- unknownJenkins Security Advisory 2026-06-242026-06-24
- unknownJenkins Security Advisory 2026-06-102026-06-10
- unknownJenkins Security Advisory 2026-05-272026-05-27
- unknownJenkins Security Advisory 2026-04-292026-04-29