MEDIUM 5.3 Microsoft
CVE-2022-43410
Jenkins Mercurial Plugin 1251.va_b_121f184902 and earlier provides information about which jobs were triggered or scheduled for polling through its webhook endpoint, including jobs the user has no permission to access.
Microsoft Security Update 2026-Aug: Jenkins Mercurial Plugin 1251.va_b_121f184902 and earlier provides information about which jobs were triggered or scheduled for polling through its webhook endpoint, including jobs the user has no permission to access.
Affected Products
- azl3 mercurial 6.5.1-1 on Azure Linux 3.0
- cm1 mercurial 5.4-2 on CBL Mariner 1.0
- cbl2 mercurial 6.0.3-2 on CBL Mariner 2.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-43410
- https://nvd.nist.gov/vuln/detail/CVE-2022-43410
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-08-06 via Microsoft. Affected: azl3 mercurial 6.5.1-1 on Azure Linux 3.0, cm1 mercurial 5.4-2 on CBL Mariner 1.0, cbl2 mercurial 6.0.3-2 on CBL Mariner 2.0.
vulnfeed aggregates 8893 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.