Описание
Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into a generated SSH wrapper script, allowing attackers able to control the name of a build's working directory to execute arbitrary operating system commands on the agent.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 6.6.1 (исключая)
cpe:2.3:a:jenkins:git_client:*:*:*:*:*:jenkins:*:*
EPSS
Процентиль: 17%
0.00253
Низкий
5 Medium
CVSS3
Дефекты
CWE-78
Связанные уязвимости
CVSS3: 5
github
2 месяца назад
Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into a generated SSH wrapper script, allowing attackers able to control the name of a build's working directory to execute arbitrary operating system commands on the agent.
EPSS
Процентиль: 17%
0.00253
Низкий
5 Medium
CVSS3
Дефекты
CWE-78