PT-2022-26901 · Jenkins · Jenkins Katalon Plugin+1
Daniel Beck
·
Published
2022-10-19
·
Updated
2023-11-01
·
CVE-2022-43416
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Jenkins Katalon Plugin versions 1.0.32 and earlier
Description
The issue allows attackers who can control agent processes to invoke Katalon on the Jenkins controller with attacker-controlled version, install location, and arguments. Additionally, attackers who can create files on the Jenkins controller, such as those with Item/Configure permission, can invoke arbitrary OS commands. This is due to an agent/controller message that does not limit where it can be executed and allows invoking Katalon with configurable arguments.
Recommendations
For Jenkins Katalon Plugin versions 1.0.32 and earlier, update to version 1.0.33 or later, which changes the message type to controller-to-agent, preventing execution on the controller. As a temporary workaround, consider restricting access to the Katalon plugin to minimize the risk of exploitation. Avoid using the Katalon plugin with configurable arguments until the issue is resolved.
Fix
Protection Mechanism Failure
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins
Jenkins Katalon Plugin