CVE Database
/

CVE-2022-25188

Back to search

CVE-2022-25188

Published: Feb 15, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

Jenkins Fortify Plugin 20.2.34 and earlier does not sanitize the appName and appVersion parameters of its Pipeline steps, allowing attackers with Item/Configure permission to write or overwrite .xml files on the Jenkins controller file system with content not controllable by the attacker.

VendorProductVersions

Jenkins project

Jenkins Fortify Plugin

affected
unspecified - <= 20.2.34

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now