Security readout for executives and security teams
Plain-English summary
Jenkins Build-Publisher Plugin 1.22 and earlier has a CSRF flaw that can let an attacker trick a logged-in Jenkins user into causing serious controller configuration damage. The reported impact is replacing any config.xml file on the Jenkins controller filesystem with an empty file, which can disrupt jobs or Jenkins behavior.
Executive priority
Treat this as high priority for Jenkins environments using the affected plugin. It can damage central CI/CD configuration, potentially interrupting delivery pipelines and weakening operational control, even though active exploitation is not evidenced in the provided sources.
Technical view
The issue is CWE-352 in a Build-Publisher Plugin API endpoint. With network access, low privileges, and user interaction, an attacker can supply a crafted file name that causes arbitrary Jenkins controller config.xml files to be emptied. CVSS 3.1 is 8.0 with high confidentiality, integrity, and availability impact.
Likely exposure
Exposure is limited to Jenkins environments running Build-Publisher Plugin 1.22 or earlier. Risk is higher where Jenkins is reachable by many users, where low-privileged accounts exist, or where administrators may browse attacker-controlled pages while authenticated to Jenkins.
Exploitation context
The source bundle does not show CISA KEV listing or cited active exploitation. Exploitation requires user interaction and at least low privileges, but the potential outcome is severe because Jenkins controller configuration files can be destroyed.
Researcher notes
Key constraints are CSRF, required user interaction, and low privileges per CVSS. The most important exposure question is whether Build-Publisher Plugin 1.22 or earlier is installed. The provided evidence does not establish a fixed version, exploit publication, or active exploitation.
Mitigation direction
- Inventory Jenkins instances for Build-Publisher Plugin version 1.22 or earlier.
- Review the Jenkins advisory and plugin release notes for vendor-supported remediation.
- Restrict Jenkins access to trusted users and networks while remediation is assessed.
- Back up Jenkins controller configuration before making plugin or platform changes.
- Remove or disable unnecessary vulnerable plugin use where business impact permits.
Validation and detection
- Check installed Jenkins plugins and confirm whether Build-Publisher is present.
- Record the installed Build-Publisher Plugin version on each Jenkins controller.
- Confirm whether Jenkins controller config.xml backups exist and can be restored.
- Review Jenkins access logs for suspicious API activity around the plugin.
- Verify remediation against the Jenkins advisory before closing the finding.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-352: User-session and phishing behavior lookup
Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2022-41232 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- High
- CVSS
- 8 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H2.15.9Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
8HighVector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Source materials
- CVE List V5 sourceCVE List V5
- https://www.jenkins.io/security/advisory/2022-09-21/#SECURITY-2139CVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Cross-Site Request Forgery (CSRF)
Cross-Site Request Forgery (CSRF) represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
