PT-2022-17128 · Jenkins · Jenkins Fortify Plugin+1

Matt Sicker

·

Published

2022-02-15

·

Updated

2023-11-30

·

CVE-2022-25188

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Fortify Plugin versions 20.2.34 and earlier
Description The issue allows attackers with Item/Configure permission to write or overwrite .xml files on the Jenkins controller file system. This is due to the lack of sanitization of the appName and appVersion parameters in the Pipeline steps. The attackers cannot control the content of the files.
Recommendations For versions 20.2.34 and earlier, update to version 20.2.35 or later, which sanitizes the appName and appVersion parameters of its Pipeline steps.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-25188
GHSA-23H5-8PH6-7RFC

Affected Products

Jenkins
Jenkins Fortify Plugin