PT-2022-17115 · Jenkins · Jenkins Pipeline: Groovy Plugin+1

Published

2022-02-15

·

Updated

2023-11-30

·

CVE-2022-25176

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Pipeline: Groovy Plugin versions 2648.va9433432b33c and earlier
Description The issue allows attackers who can configure Pipelines to read arbitrary files on the Jenkins controller file system. This is because the plugin follows symbolic links to locations outside of the checkout directory for the configured SCM when reading the script file, typically Jenkinsfile, for Pipelines.
Recommendations For versions 2648.va9433432b33c and earlier, consider restricting access to the Jenkins controller file system to minimize the risk of exploitation. As a temporary workaround, limit the ability to configure Pipelines to trusted users only until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-25176
GHSA-6473-GQRJ-4P65
RHSA-2022:0871
RHSA-2022:1021
RHSA-2022:1025
RHSA-2022:1248
RHSA-2022:1420
RHSA-2022:1620

Affected Products

Jenkins
Jenkins Pipeline: Groovy Plugin