PT-2022-15861 · Jenkins · Jenkins Debian Package Builder Plugin+1

Published

2022-01-12

·

Updated

2023-11-30

·

CVE-2022-23118

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Jenkins Debian Package Builder Plugin versions 1.6.11 and earlier
Description The issue allows agents to invoke command-line git at an attacker-specified path on the controller. This enables attackers who can control agent processes to invoke arbitrary OS commands on the controller.
Recommendations For Jenkins Debian Package Builder Plugin versions 1.6.11 and earlier, consider disabling the functionality that allows agents to invoke command-line git at an attacker-specified path on the controller until a patch is available. Restrict access to the controller to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Protection Mechanism Failure

Exposure of Resource to Wrong Sphere

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2022-23118
GHSA-8XJP-RP29-V5J8

Affected Products

Jenkins
Jenkins Debian Package Builder Plugin