CVE Database
/

CVE-2022-25175

Back to search

CVE-2022-25175

Published: Feb 15, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier uses the same checkout directories for distinct SCMs for the readTrusted step, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.

VendorProductVersions

Jenkins project

Jenkins Pipeline: Multibranch Plugin

unaffected
2.26.1
unaffected
2.23.1
unaffected
696.698.v9b4218eea50f
affected
unspecified - <= 706.vd43c65dec013

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now