Lucene search

K
cvelistJenkinsCVELIST:CVE-2022-25176
HistoryFeb 15, 2022 - 4:10 p.m.

CVE-2022-25176

2022-02-1516:10:55
jenkins
www.cve.org
6
jenkins
pipeline
groovy
plugin
vulnerability
arbitrary files

AI Score

7.6

Confidence

High

EPSS

0.001

Percentile

28.4%

Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier follows symbolic links to locations outside of the checkout directory for the configured SCM when reading the script file (typically Jenkinsfile) for Pipelines, allowing attackers able to configure Pipelines to read arbitrary files on the Jenkins controller file system.

CNA Affected

[
  {
    "product": "Jenkins Pipeline: Groovy Plugin",
    "vendor": "Jenkins project",
    "versions": [
      {
        "lessThanOrEqual": "2648.va9433432b33c",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "status": "unaffected",
        "version": "2.94.1"
      },
      {
        "status": "unaffected",
        "version": "2.92.1"
      }
    ]
  }
]

AI Score

7.6

Confidence

High

EPSS

0.001

Percentile

28.4%