CVE-2022-27217
Status: ModifiedMedium (6.5)—
Jenkins Vmware vRealize CodeStream Plugin 1.2 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Base score: 6.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.95%
- Percentile among all scored CVEs: 60
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-522
References
Raw JSON (NVD)
Show
{
"id": "CVE-2022-27217",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
"authentication": "SINGLE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "jenkinsci-cert@googlegroups.com",
"affectedData": [
{
"vendor": "Jenkins project",
"product": "Jenkins Vmware vRealize CodeStream Plugin",
"versions": [
{
"status": "affected",
"version": "unspecified",
"versionType": "custom",
"lessThanOrEqual": "1.2"
},
{
"status": "unknown",
"version": "next of 1.2",
"lessThan": "unspecified",
"versionType": "custom"
}
]
}
]
}
],
"published": "2022-03-15T17:15:12.777",
"references": [
{
"url": "http://www.openwall.com/lists/oss-security/2022/03/15/2",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "jenkinsci-cert@googlegroups.com"
},
{
"url": "https://www.jenkins.io/security/advisory/2022-03-15/#SECURITY-2238",
"tags": [
"Vendor Advisory"
],
"source": "jenkinsci-cert@googlegroups.com"
},
{
"url": "http://www.openwall.com/lists/oss-security/2022/03/15/2",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.jenkins.io/security/advisory/2022-03-15/#SECURITY-2238",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-522"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Jenkins Vmware vRealize CodeStream Plugin 1.2 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system."
},
{
"lang": "es",
"value": "El Plugin Vmware vRealize CodeStream de Jenkins versiones 1.2 y anteriores, almacena las contraseñas sin cifrar en los archivos config.xml del trabajo en el controlador de Jenkins donde pueden ser visualizados por usuarios con permiso de Lectura Extendida, o acceso al sistema de archivos del controlador de Jenkins"
}
],
"lastModified": "2026-06-17T04:36:31.037",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:jenkins:vmware_vrealize_codestream:*:*:*:*:*:jenkins:*:*",
"vulnerable": true,
"matchCriteriaId": "41430DE4-EC4C-4C4D-9BA1-76F134C525C8",
"versionEndIncluding": "1.2"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "jenkinsci-cert@googlegroups.com"
}