Lucene search

K
osvGoogleOSV:GHSA-G9FX-6J5C-GRMW
HistoryFeb 16, 2022 - 12:01 a.m.

Improper Neutralization of Special Elements used in an OS Command in Jenkins Pipeline: Shared Groovy Libraries Plugin

2022-02-1600:01:36
Google
osv.dev
8

0.001 Low

EPSS

Percentile

46.1%

Jenkins Pipeline: Shared Groovy Libraries Plugin prior to 561.va_ce0de3c2d69, 2.21.1, and 2.18.1 uses the same checkout directories for distinct SCMs for Pipeline libraries, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.

0.001 Low

EPSS

Percentile

46.1%