CVE-2022-30952: Jenkins Blue Ocean
Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.
Jenkins Pipeline SCM API for Blue Ocean Plugin 1.25.3 and earlier allows attackers with Job/Configure permission to access credentials with attacker-specified IDs stored in the private per-user credentials stores of any attacker-specified user in Jenkins.
Affected products
- Jenkins Blue Ocean: up to and including 1.25.3
Published 2022-05-17. Last modified 2026-06-17.