Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-66cr-6whx-732p

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью

Описание

Jenkins improperly ensures trust separation

Jenkins prior to 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

< 1.587

1.587

EPSS

Процентиль: 83%
0.02502
Низкий

Связанные уязвимости

ubuntu
больше 10 лет назад

Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.

redhat
почти 12 лет назад

Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.

nvd
больше 10 лет назад

Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.

debian
больше 10 лет назад

Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure tru ...

EPSS

Процентиль: 83%
0.02502
Низкий