PT-2022-26901 · Jenkins · Jenkins Katalon Plugin+1

Daniel Beck

·

Published

2022-10-19

·

Updated

2023-11-01

·

CVE-2022-43416

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins Katalon Plugin versions 1.0.32 and earlier
Description The issue allows attackers who can control agent processes to invoke Katalon on the Jenkins controller with attacker-controlled version, install location, and arguments. Additionally, attackers who can create files on the Jenkins controller, such as those with Item/Configure permission, can invoke arbitrary OS commands. This is due to an agent/controller message that does not limit where it can be executed and allows invoking Katalon with configurable arguments.
Recommendations For Jenkins Katalon Plugin versions 1.0.32 and earlier, update to version 1.0.33 or later, which changes the message type to controller-to-agent, preventing execution on the controller. As a temporary workaround, consider restricting access to the Katalon plugin to minimize the risk of exploitation. Avoid using the Katalon plugin with configurable arguments until the issue is resolved.

Fix

Protection Mechanism Failure

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2022-43416
GHSA-Q6F6-6C4P-XPH4

Affected Products

Jenkins
Jenkins Katalon Plugin