Description
Jenkins Debian Package Builder Plugin 1.6.11 and earlier implements functionality that allows agents to invoke command-line `git` at an attacker-specified path on the controller, allowing attackers able to control agent processes to invoke arbitrary OS commands on the controller.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0536 | Jenkins Debian Package Builder Plugin 1.6.11 and earlier implements functionality that allows agents to invoke command-line `git` at an attacker-specified path on the controller, allowing attackers able to control agent processes to invoke arbitrary OS commands on the controller. |
Github GHSA |
GHSA-8xjp-rp29-v5j8 | Agent-to-controller security bypass in Jenkins Debian Package Builder Plugin |
References
History
Tue, 19 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-11-19T19:01:27.534Z
Reserved: 2022-01-11T00:00:00.000Z
Link: CVE-2022-23118
Updated: 2024-08-03T03:36:19.962Z
Status : Modified
Published: 2022-01-12T20:15:09.807
Modified: 2024-11-21T06:48:01.870
Link: CVE-2022-23118
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA