Description
Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the application path of the applications when configuring a deployment, allowing attackers with Item/Configure permission to upload arbitrary files from the Jenkins controller file system to the selected service.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6360 | Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the application path of the applications when configuring a deployment, allowing attackers with Item/Configure permission to upload arbitrary files from the Jenkins controller file system to the selected service. |
Github GHSA |
GHSA-j5qq-6rpm-qjgh | Jenkins Deployer Framework Plugin does not restrict application path of applications when configuring a deployment |
References
History
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-03T10:14:29.368Z
Reserved: 2022-07-27T00:00:00.000Z
Link: CVE-2022-36889
No data.
Status : Modified
Published: 2022-07-27T15:15:09.197
Modified: 2024-11-21T07:13:59.973
Link: CVE-2022-36889
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA