CVE Database
/

CVE-2022-34177

Back to search

CVE-2022-34177

Published: Jun 22, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

Jenkins Pipeline: Input Step Plugin 448.v37cea_9a_10a_70 and earlier archives files uploaded for `file` parameters for Pipeline `input` steps on the controller as part of build metadata, using the parameter name without sanitization as a relative path inside a build-related directory, allowing attackers able to configure Pipelines to create or replace arbitrary files on the Jenkins controller file system with attacker-specified content.

VendorProductVersions

Jenkins project

Jenkins Pipeline: Input Step Plugin

unaffected
447.449.v193fd29f6021
unaffected
2.12.2
affected
unspecified - <= 448.v37cea_9a_10a_70

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now