Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-25188
HistoryFeb 15, 2022 - 5:15 p.m.

Code injection

2022-02-1517:15:00
PRIOn knowledge base
www.prio-n.com
2

4.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.8%

Jenkins Fortify Plugin 20.2.34 and earlier does not sanitize the appName and appVersion parameters of its Pipeline steps, allowing attackers with Item/Configure permission to write or overwrite .xml files on the Jenkins controller file system with content not controllable by the attacker.

CPENameOperatorVersion
fortifyle20.2.34

4.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.8%