CVE-2022-30952: Jenkins Blue Ocean

Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.

Jenkins Pipeline SCM API for Blue Ocean Plugin 1.25.3 and earlier allows attackers with Job/Configure permission to access credentials with attacker-specified IDs stored in the private per-user credentials stores of any attacker-specified user in Jenkins.

Affected products

  • Jenkins Blue Ocean: up to and including 1.25.3

Published 2022-05-17. Last modified 2026-06-17.