CVE-2022-34177
Published: Jun 22, 2022
Modified: Aug 3, 2024
Description
Jenkins Pipeline: Input Step Plugin 448.v37cea_9a_10a_70 and earlier archives files uploaded for `file` parameters for Pipeline `input` steps on the controller as part of build metadata, using the parameter name without sanitization as a relative path inside a build-related directory, allowing attackers able to configure Pipelines to create or replace arbitrary files on the Jenkins controller file system with attacker-specified content.
| Vendor | Product | Versions |
|---|---|---|
Jenkins project | Jenkins Pipeline: Input Step Plugin | unaffected 447.449.v193fd29f6021unaffected 2.12.2affected unspecified - <= 448.v37cea_9a_10a_70 |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now