Lucene search

K
osvGoogleOSV:GHSA-P5X5-JG3J-2JCJ
HistoryMay 24, 2022 - 5:10 p.m.

OS command injection in CryptoMove Plugin

2022-05-2417:10:30
Google
osv.dev
8

0.009 Low

EPSS

Percentile

82.6%

CryptoMove Plugin 0.1.33 and earlier allows the configuration of an OS command to execute as part of its build step configuration. This command will be executed on the Jenkins controller as the OS user account running Jenkins, allowing user with Job/Configure permission to execute an arbitrary OS command on the Jenkins controller.

0.009 Low

EPSS

Percentile

82.6%

Related for OSV:GHSA-P5X5-JG3J-2JCJ