Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-55163
HistoryMar 17, 2022 - 12:00 a.m.

Jenkins Semantic Versioning Plugin Access Control Error Vulnerability

2022-03-1700:00:00
China National Vulnerability Database
www.cnvd.org.cn
5

0.001 Low

EPSS

Percentile

28.8%

Jenkins and Jenkins Plugin are both Jenkins open source products.Jenkins is an application. An open source automation server, Jenkins provides hundreds of plugins to support building, deploying, and automating any project.Jenkins Plugin is an application.An access control error vulnerability exists in Jenkins Semantic Versioning Plugin 1.13 and prior versions, which stems from the program’s failure to restrict the execution of agent The vulnerability stems from an unrestricted execution of controller/agent messages and an unrestricted file path that can be parsed, which can be exploited by an attacker to extract secrets from the Jenkins Builder or server-side request forgery.

0.001 Low

EPSS

Percentile

28.8%

Related for CNVD-2022-55163