Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-29047

Опубликовано: 12 апр. 2022
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

Jenkins Pipeline: Shared Groovy Libraries Plugin 564.ve62a_4eb_b_e039 and earlier, except 2.21.3, allows attackers able to submit pull requests (or equivalent), but not able to commit directly to the configured SCM, to effectively change the Pipeline behavior by changing the definition of a dynamically retrieved library in their pull request, even if the Pipeline is configured to not trust them.

A flaw was found in the Jenkins Pipeline: Shared Groovy Libraries plugin. The Jenkins Pipeline: Shared Groovy Libraries plugin allows attackers to submit pull requests. However, the attacker cannot commit directly to the configured Source Control Management (SCM) to effectively change the Pipeline behavior by changing the definition of a dynamically retrieved library in their pull request, even with the Pipeline configured not to trust them.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.11jenkins-2-pluginsNot affected
OCP-Tools-4.12-RHEL-8jenkins-2-pluginsFixedRHSA-2023:106406.03.2023
Red Hat OpenShift Container Platform 4.7jenkins-2-pluginsFixedRHSA-2022:490910.06.2022
Red Hat OpenShift Container Platform 4.8jenkins-2-pluginsFixedRHSA-2023:001712.01.2023
Red Hat OpenShift Container Platform 4.9jenkins-2-pluginsFixedRHSA-2022:220518.05.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-288
https://bugzilla.redhat.com/show_bug.cgi?id=2074855Libraries: Untrusted users can modify some Pipeline libraries in Pipeline Shared Groovy Libraries Plugin

EPSS

Процентиль: 48%
0.00245
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
почти 4 года назад

Jenkins Pipeline: Shared Groovy Libraries Plugin 564.ve62a_4eb_b_e039 and earlier, except 2.21.3, allows attackers able to submit pull requests (or equivalent), but not able to commit directly to the configured SCM, to effectively change the Pipeline behavior by changing the definition of a dynamically retrieved library in their pull request, even if the Pipeline is configured to not trust them.

CVSS3: 7.3
github
почти 4 года назад

Untrusted users can modify some Pipeline libraries in Jenkins Pipeline: Deprecated Groovy Libraries Plugin

EPSS

Процентиль: 48%
0.00245
Низкий

7.3 High

CVSS3