CVE-2022-25183
Published: Feb 15, 2022
Modified: Aug 3, 2024
Description
Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the names of Pipeline libraries to create cache directories without any sanitization, allowing attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM using specially crafted library names if a global Pipeline library configured to use caching already exists.
| Vendor | Product | Versions |
|---|---|---|
Jenkins project | Jenkins Pipeline: Shared Groovy Libraries Plugin | affected unspecified - <= 552.vd9cc05b8a2e1affected 2.21 - < unspecifiedunaffected 2.21.1 |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now