Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-45381

Опубликовано: 15 нояб. 2022
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

Jenkins Pipeline Utility Steps Plugin 2.13.1 and earlier does not restrict the set of enabled prefix interpolators and bundles versions of Apache Commons Configuration library that enable the 'file:' prefix interpolator by default, allowing attackers able to configure Pipelines to read arbitrary files from the Jenkins controller file system.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jenkins:pipeline_utility_steps:*:*:*:*:*:jenkins:*:*
Версия до 2.13.2 (исключая)

EPSS

Процентиль: 45%
0.00224
Низкий

8.1 High

CVSS3

Дефекты

CWE-22
CWE-22

Связанные уязвимости

CVSS3: 8.1
redhat
около 3 лет назад

Jenkins Pipeline Utility Steps Plugin 2.13.1 and earlier does not restrict the set of enabled prefix interpolators and bundles versions of Apache Commons Configuration library that enable the 'file:' prefix interpolator by default, allowing attackers able to configure Pipelines to read arbitrary files from the Jenkins controller file system.

CVSS3: 7.5
github
около 3 лет назад

Arbitrary file read vulnerability in Jenkins Pipeline Utility Steps Plugin

EPSS

Процентиль: 45%
0.00224
Низкий

8.1 High

CVSS3

Дефекты

CWE-22
CWE-22