CVE Database
/

CVE-2022-25183

Back to search

CVE-2022-25183

Published: Feb 15, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the names of Pipeline libraries to create cache directories without any sanitization, allowing attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM using specially crafted library names if a global Pipeline library configured to use caching already exists.

VendorProductVersions

Jenkins project

Jenkins Pipeline: Shared Groovy Libraries Plugin

affected
unspecified - <= 552.vd9cc05b8a2e1
affected
2.21 - < unspecified
unaffected
2.21.1

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now