Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ffgg-vphh-v273

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Incomplete List of Disallowed Inputs in Jenkins

Jenkins before versions 2.44 and 2.32.2 is vulnerable to an improper blacklisting of the Pipeline metadata files in the agent-to-master security subsystem. This could allow metadata files to be written to by malicious agents (SECURITY-358).

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

<= 2.32.1

2.32.2

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.34, <= 2.43

2.44

EPSS

Процентиль: 38%
0.00165
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-184

Связанные уязвимости

CVSS3: 3.1
ubuntu
больше 7 лет назад

jenkins before versions 2.44, 2.32.2 is vulnerable to an improper blacklisting of the Pipeline metadata files in the agent-to-master security subsystem. This could allow metadata files to be written to by malicious agents (SECURITY-358).

CVSS3: 3.1
redhat
около 9 лет назад

jenkins before versions 2.44, 2.32.2 is vulnerable to an improper blacklisting of the Pipeline metadata files in the agent-to-master security subsystem. This could allow metadata files to be written to by malicious agents (SECURITY-358).

CVSS3: 3.1
nvd
больше 7 лет назад

jenkins before versions 2.44, 2.32.2 is vulnerable to an improper blacklisting of the Pipeline metadata files in the agent-to-master security subsystem. This could allow metadata files to be written to by malicious agents (SECURITY-358).

CVSS3: 3.1
debian
больше 7 лет назад

jenkins before versions 2.44, 2.32.2 is vulnerable to an improper blac ...

EPSS

Процентиль: 38%
0.00165
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-184