Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h648-gj34-5x4r

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Agent-to-controller security bypass in Jenkins Squash TM Publisher (Squash4Jenkins) Plugin allows writing arbitrary files

Jenkins Squash TM Publisher (Squash4Jenkins) Plugin 1.0.0 and earlier implements an agent-to-controller message that does not implement any validation of its input, allowing attackers able to control agent processes to replace arbitrary files on the Jenkins controller file system with an attacker-controlled JSON string.

Пакеты

Наименование

org.jenkins-ci.plugins:squashtm-publisher-plugin

maven
Затронутые версииВерсия исправления

<= 1.0.0

Отсутствует

EPSS

Процентиль: 32%
0.00125
Низкий

8.1 High

CVSS3

Дефекты

CWE-693

Связанные уязвимости

CVSS3: 8.1
nvd
около 4 лет назад

Jenkins Squash TM Publisher (Squash4Jenkins) Plugin 1.0.0 and earlier implements an agent-to-controller message that does not implement any validation of its input, allowing attackers able to control agent processes to replace arbitrary files on the Jenkins controller file system with an attacker-controlled JSON string.

EPSS

Процентиль: 32%
0.00125
Низкий

8.1 High

CVSS3

Дефекты

CWE-693