CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2022-30970

unknowncovered by 1 sourcefirst seen 2022-05-17
Affects plugin: Application Detector Affects plugin: Autocomplete Parameter Affects plugin: Blue Ocean Affects plugin: Git Affects plugin: GitLab Affects plugin: Global Variable String Parameter Affects plugin: JDK Parameter Affects plugin: Mercurial Affects plugin: Multiselect parameter Affects plugin: Pipeline SCM API for Blue Ocean Affects plugin: Pipeline: Groovy Affects plugin: Promoted Builds (Simple) Affects plugin: Random String Parameter Affects plugin: REPO Affects plugin: Rundeck Affects plugin: Script Security Affects plugin: Selection tasks Affects plugin: SSH Affects plugin: Storable Configs Affects plugin: vboxwrapper Affects plugin: windows-slaves

CSIRTS triage

What
Multiple plugins in Jenkins are affected by various vulnerabilities.
Who is affected
Deployments of Jenkins with the affected plugins.
Urgency
Remediation is urgent due to the potential for exploitation, although the severity is unknown.
Action
Update the affected plugins to their latest versions.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2022-30970

Get an email if CVE-2022-30970 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2022-30970

CVE.org record

Embed the live status

CVE-2022-30970 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2022-30970 status](https://www.csirts.com/badge/CVE-2022-30970)](https://www.csirts.com/cve/CVE-2022-30970)