Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-66cr-6whx-732p

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью

Описание

Jenkins improperly ensures trust separation

Jenkins prior to 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

< 1.587

1.587

EPSS

Процентиль: 64%
0.00476
Низкий

Связанные уязвимости

ubuntu
около 10 лет назад

Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.

redhat
больше 11 лет назад

Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.

nvd
около 10 лет назад

Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.

debian
около 10 лет назад

Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure tru ...

EPSS

Процентиль: 64%
0.00476
Низкий