Lucene search

K
osvGoogleOSV:GHSA-JPXJ-VGQ5-PRJC
HistoryJan 13, 2022 - 12:01 a.m.

OS command execution vulnerability in Jenkins Docker Commons Plugin

2022-01-1300:01:03
Google
osv.dev
7

8.5 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

60.8%

Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS command execution vulnerability exploitable by attackers with Item/Configure permission or able to control the contents of a previously configured job’s SCM repository.

8.5 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

60.8%