Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-45381
HistoryNov 15, 2022 - 8:15 p.m.

Default configuration

2022-11-1520:15:00
PRIOn knowledge base
www.prio-n.com
6
jenkins
pipeline
security
apache commons configuration

7.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.7%

Jenkins Pipeline Utility Steps Plugin 2.13.1 and earlier does not restrict the set of enabled prefix interpolators and bundles versions of Apache Commons Configuration library that enable the ‘file:’ prefix interpolator by default, allowing attackers able to configure Pipelines to read arbitrary files from the Jenkins controller file system.

CPENameOperatorVersion
pipeline_utility_stepslt2.13.2

7.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.7%