Логотип exploitDog
bind:CVE-2022-25183
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-25183

Количество 3

Количество 3

redhat логотип

CVE-2022-25183

почти 4 года назад

Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the names of Pipeline libraries to create cache directories without any sanitization, allowing attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM using specially crafted library names if a global Pipeline library configured to use caching already exists.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2022-25183

почти 4 года назад

Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the names of Pipeline libraries to create cache directories without any sanitization, allowing attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM using specially crafted library names if a global Pipeline library configured to use caching already exists.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-pfwp-q984-w7wh

почти 4 года назад

Jenkins Pipeline: Deprecated Groovy Libraries Plugin Protection Mechanism Failure

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-25183

Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the names of Pipeline libraries to create cache directories without any sanitization, allowing attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM using specially crafted library names if a global Pipeline library configured to use caching already exists.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-25183

Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the names of Pipeline libraries to create cache directories without any sanitization, allowing attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM using specially crafted library names if a global Pipeline library configured to use caching already exists.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-pfwp-q984-w7wh

Jenkins Pipeline: Deprecated Groovy Libraries Plugin Protection Mechanism Failure

CVSS3: 8.8
1%
Низкий
почти 4 года назад

Уязвимостей на страницу