CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2022-23116

unknowncovered by 1 sourcefirst seen 2022-01-12
Affects Jenkins Core Affects plugin: Active Directory Affects plugin: Badge Affects plugin: batch task Affects plugin: Bitbucket Branch Source Affects plugin: Configuration as Code Affects plugin: Conjur Secrets Affects plugin: Credentials Binding Affects plugin: Debian Package Builder Affects plugin: Docker Commons Affects plugin: HashiCorp Vault Affects plugin: Mailer Affects plugin: Matrix Project Affects plugin: Metrics Affects plugin: Publish Over SSH Affects plugin: SSH Agent Affects plugin: Warnings

CSIRTS triage

What
Multiple plugins in Jenkins have vulnerabilities that could potentially be exploited.
Who is affected
Deployments of Jenkins Core and the listed plugins are affected.
Urgency
Remediation is necessary as vulnerabilities exist, although exploitation status is currently unknown.
Action
Update to the latest versions of Jenkins Core and the affected plugins.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2022-23116

Get an email if CVE-2022-23116 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2022-23116

CVE.org record

Embed the live status

CVE-2022-23116 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2022-23116 status](https://www.csirts.com/badge/CVE-2022-23116)](https://www.csirts.com/cve/CVE-2022-23116)